Okta SSO
min

Okta SSO

Associate Okta Groups with Solsta Teams

You can link an Okta Group to a Solsta Team. This lets any member of that group be automatically enrolled into the associated Solsta Team, inheriting its roles and entitlements.

Requirements

Before you begin, please ensure:

  • You have admin rights within Okta to view groups and app credentials
  • Solsta is registered as an OpenID Connect (OIDC) app in Okta
  • Your Okta-to-Solsta SSO integration is active. If this hasn’t been set up for your organization, please open a support ticket to initiate the process
  • You have the Organization Admin role in Solsta

Redirect URI:

Use this URI when you register the Solsta App in Okta:

https://snxd.auth0.com/login/callback

Key Concepts & Sync Behavior

To ensure a smooth deployment, administrators should note the following behavior regarding user visibility and provisioning:

  • Just-In-Time (JIT) Provisioning: Solsta uses JIT provisioning. This means a user will not appear in the Solsta team list until they have successfully launched and logged into the Solsta desktop client.
  • No Invites Required: When using Okta group synchronization, you do not need to send manual email invites. The Okta group membership acts as the authorization.
  • The "First Launch" Sequence:
    • Admin maps the Okta group to a Solsta Team
    • Admin notifies users they are cleared to log in
    • User launches the Solsta client and authenticates via SSO
    • The user’s record and team membership are then created and become visible in the Solsta UI for organization admins

Obtain Group Names from Okta

Log in to Okta and get the name of the group you want to connect to a Solsta team.

Connect SSO Group to Solsta Team

  1. Log in to Solsta as an Organization Admin
  2. From the navigation pane, click on Teams
  3. Click on the Create Team button on the top right
  4. Fill out the Name field and (optional) Description and Picture URL fields
  5. In SSO Group Link, paste the plain-text name of your Okta Group (e.g., EngineeringTeam).
  6. Click Ok

Create Team for Okta Group
Note: An SSO Group can only be linked to a team when that team is initially created. You are not able to edit an existing team in Solsta to connect it to an SSO group. You can always delete existing groups and create new ones in order to link a new group. The name and description of existing teams can be edited by clicking the Edit button from the Actions column of the Team screen

Verify the Sync

Because users appear only after their first login, use the following steps to verify the connection:

  1. Confirm the SSO Group Link name in Solsta matches the name of the group in Okta exactly
  2. Ask a "pilot" user from the Okta group to launch the Solsta client and log in
  3. Refresh the Solsta Admin UI (refresh button or navigating away and back to the Team page). The pilot user should now appear within the designated Team.

Result

Once the team sync is verified, the setup is live. Instruct the rest of the team to download and launch the Solsta client.

When any member of that Okta group signs in through SSO, they are automatically added to the linked Solsta Team and granted the same entitlements.

References:

Do not wait for users to appear in the Admin UI before instructing them to launch the client. They will only appear after their first successful authentication.