How to Configure the Profile Application in Okta
3 min
overview & requirements this article is designed to assist administrators and technical teams in integrating okta's powerful identity and access management capabilities with profile by following our step by step instructions, you'll be able to establish a seamless and secure user authentication process, enable single sign on (sso) for a streamlined user experience, and efficiently manage user access through okta's centralized platform requirements an okta account sso is a licensed module and will need to be setup by intrahealth please contact your intrahealth representative if you wish to enable this feature configuration process okta's admin console setting up the profile application and user management in the admin console, go to applications / applications click create app integration to create an oidc app integration, select oidc openid connect as the sign in method choose the type of application to integrate with okta select native application click next in the general settings section, enter the following information for the app integration name field , enter an appropriate name to indicate that this integration is intended for use with profile (e g 'profile integration') for the grant type , check the following options authorization code interaction code refresh token in both the sign in redirect urls and sign out redirect urls fields you will need to replace the default information with information you will gather from within profile for the sign in redirect urls field in the okta admin console in profile, go to organisation / preferences / setup / internet / messages tab copy the information from within the organisation web url field paste the information taken from profile and add it to the sign in redirect urls field in the okta admin console add the additional path " /sso/auth " for example, it could read as 'https //mycompany com/sso/auth' for the sign out redirect urls field in the okta admin console in profile, go to organisation / preferences / setup / internet / messages tab copy the information from within the organisation web url field paste the information taken from profile and add it to the sign out redirect urls field in the okta admin console add the additional path " /sso/logout " for example, it could read as 'https //mycompany com/sso/logout' in the assignments section of okta's application setup, administrators can manage the assignment of the application to specific users or groups within their organization this section enables precise control over which individuals or groups can access and utilize the application's features and resources, streamlining the allocation of application permissions and ensuring secure and efficient access management within the organization note if an okta user is not assigned specifically to this profile application within okta, this user will not be able to access profile via okta click the save button found at the bottom of the page you will be brought to a new screen automatically, starting in the general tab general tab the client credentials section contains important information necessary for authentication flows client id this is the public identifier required by all oauth flows this identifier is randomly generated when you create the app integration this client id will be entered into profile's client id field client authentication choose the method to use for client authentication client secret selecting this option displays a panel where you can generate a secret for use by the client this value is known only to okta and your app integration click save to generate the client secret you can view or copy the client secret if you have a second client secret, you can change the status to select the active secret the client secret will be entered in profile's client secret field click save to commit any changes to your client credentials if you changed your client authentication method, see change client authentication methods https //help okta com/en us/content/topics/apps/oauth client cred mgmt htm#change , in the okta help center, for information on how existing secrets and keys are affected for the refresh token setting, check the use persistent token option for the user consent , click the require consent option sign on tab click on the sign on tab keep the default information as is learn more profile's sso capabilities with okta docid\ iazfooltgybo7h0brvmdxhow to create and configure a profile desktop shortcut for the okta sso capabilities docid\ ypf5tifhnvqcmm8 nfa7ahow to configure sso for okta in profile docid 1xwerjfxjsvpfdpq twc5troubleshooting guide sso with okta docid\ otb1hsurkqk3iwromjyxfhow to log into profile using sso with okta docid\ pmgyx2vt 2xlcr96qyfkehow to log out when using sso with okta docid\ jy800lubonaari5qutyve