Skip to main content

Set Up Okta Integration

To sign in to BioStar Air with Okta, the ID administrator must create an OIDC application in Okta. Link it to the SSO settings in BioStar Air.

Connect Okta SSO

BioStar Air: Prepare redirect URI

  1. Click SettingsSite in the left sidebar of BioStar Air.

  2. Click the SSO & SCIM tab.

  3. Select Okta under Identity Provider.

  4. Copy the URI value shown in the Redirect URI field.

Okta: Create an app

  1. Sign in to the Okta Admin Console.

  2. Go to Applications and ResourcesApplications.

  3. Click Create App Integration.

  4. Under Sign-in method, select OIDC - OpenID Connect.

  5. Under Application type, select Web Application so you can obtain a client secret.

  6. Click Next.

  7. In App Integration name, enter 'BioStar Air'.

  8. Paste the URI copied in the #bsairRedirect step into the input field under Sign-in redirect URIs.

  9. Go to Assignments, then select Allow everyone in your organization to access.

  10. Click Save.

Okta: Copy app client information

  1. After creating the application, copy Client ID and Client Secret from the General tab.

  2. Click the profile in the upper-right corner, then copy Okta Domain.

Enter the copied Client ID, Client Secret, and Okta Domain in the next step.

BioStar Air: Configure SSO

  1. Return to the BioStar Air settings page, then enter the values copied in the #copyClientinfo step into each field.

    • Client ID: Client ID

    • Client Secret: Client Secret

    • Okta Domain: Okta Domain

  2. In the Email Domain field, enter your organization's email domain.

  3. Click Save & Validate.

After the system saves and verifies successfully, it automatically generates the value for Discovery URL.

Connect Okta SCIM provisioning

BioStar Air: Copy SCIM token

  1. Click SettingsSite in the left sidebar of BioStar Air.

  2. Click the SSO & SCIM tab.

  3. In the SCIM Provisioning section, copy the SCIM Endpoint URL value.

  4. Click Generate Token.

  5. In the Token Generation Complete dialog box, copy the token.

Info
  • Copy the generated token immediately. Copy the token only when you generate it. After you close the dialog box, you cannot copy the token again.

  • If you lose the token, click Rotate Token to generate a new token. Enter the new token in the identity provider again.

  • In the next step, enter the SCIM endpoint URL and token copied in this step.

Okta: Create a SCIM provisioning app

  1. In the Okta Admin Console, go to Applications and ResourcesApplications.

  2. Click Browse App Catalog.

  3. Search for 'SCIM 2.0 Test App'.

  4. In the search results, select SCIM 2.0 Test App (Header Auth).

  5. Click Add Integration.

  6. In the Application label field, enter 'BioStar Air SCIM'.

  7. Click Next.

  8. In Sign-on options, scroll down without changing settings, and click Done.

Okta: API integration settings

  1. After creating the provisioning app, click the Provisioning tab.

  2. Click Configure API Integration.

  3. Click Enable API integration.

  4. Enter the SCIM endpoint URL and SCIM bearer token from #copyToken into the Base URL and API Token fields.

  5. To test synchronization, click Test API Credentials.

  6. Click Save.

  7. Click the Provision tab to set group push behavior.

  8. Click Edit, then enable the following attributes.

    • Create Users

    • Update User Attributes

    • Deactivate Users

  9. Click Save to save the changes.

Push IdP groups to BioStar Air

To push IdP groups to BioStar Air, first prepare user groups and users in Okta. After preparing user groups and users, push them to BioStar Air via SCIM.

Okta: Assign user groups

  1. Sign in to the Okta Admin Console.

  2. Go to Applications and ResourcesApplications.

  3. Select the SCIM application.

  4. Click the Assignments tab.

  5. Click AssignAssign to Groups.

  6. In the user group to assign to the SCIM application, click Assign.

  7. After assigning the group, click Done.

Okta: Push user groups

  1. Click the Push Groups tab.

  2. Click Push GroupsFind groups by name.

  3. In the input field, enter the group name to push.

  4. When a matching user group appears, select it.

  5. After selecting a user group, click Save or Save & Another to add it.

  6. Check the pushed user groups on the Push Groups tab.

BioStar Air: Check the connection

  1. Click SettingsSite in the left sidebar of BioStar Air.

  2. Click the SSO & SCIM tab.

  3. In the SCIM Provisioning section, check for the Connected indicator.

Group mapping

After connecting SSO and SCIM and pushing IdP groups, the site administrator must map them to BioStar Air groups.

Mapping rules

  • You can map multiple IdP groups to a single BioStar Air user group.

  • A BioStar Air user group must be empty before mapping.

  • BioStar Air groups with members cannot serve as mapping targets.

  • Only the site master administrator can manage IdP group mapping.

  • The system locks the role after mapping an IdP group to the master role.

Map administrator roles and user groups

  1. Click SettingsSite in the left sidebar of BioStar Air.

  2. Click the SSO & SCIM tab.

  3. Go to the Group Mapping section and click Add.

  4. From IdP Group, select an IdP group.

  5. In Mapping Target, select Admin Role or Local User Group based on the selected IdP group.

  6. Depending on the mapping target, assign an administrator role or select a user group.

  7. Click Save to save the mapping.

The Group Mapping section shows IdP groups and their mapped BioStar Air groups.

Info

Manage synchronized admins, users, and groups

With provisioning enabled, BioStar Air shows whether each admin, user, and group is local or synchronized from the identity provider.

  • In SettingsAdmins & Technicians, check the Identity Source column in the admin list.

  • In User ManagementUsers, check the Identity Source column in the user list.

  • In User ManagementUser Groups, check the Identity Source column in the user group list.

How SCIM-synced entries work

  • Manually created users and admins remain manually managed.

  • BioStar Air prevents manual deletion of SCIM-synced entries.

  • BioStar Air prevents manually adding or removing users from SCIM-synced groups.

  • Manually changing a synchronized entry locally sets the status to Override. Run Release Override to cancel local changes and return the entry to SCIM management.

Sign in to Okta

After completing the Okta SSO connection, users can sign in with their Okta accounts on the BioStar Air login screen.

  1. On the BioStar Air login screen, click Sign in with Okta.

  2. Enter the organization's email address or domain in the Email Address or Domain field. (For example, user@company.com or company)

  3. Click Continue.

  4. When the Okta sign-in page opens, enter the email address and password for the organization account.

  5. After authentication is complete, you are automatically redirected to BioStar Air, completing the sign-in process.

Info

If Okta SSO is not set up for the entered email domain, an error message appears. Contact the site administrator.

Was this page helpful?