{"id":185224,"date":"2024-02-13T15:40:14","date_gmt":"2024-02-13T20:40:14","guid":{"rendered":"https:\/\/optinmonster.com\/?post_type=optinmonster_docs&#038;p=185224"},"modified":"2025-07-28T07:00:11","modified_gmt":"2025-07-28T11:00:11","slug":"how-to-enable-okta-sso-and-mfa-for-optinmonster","status":"publish","type":"optinmonster_docs","link":"https:\/\/optinmonster.com\/docs\/how-to-enable-okta-sso-and-mfa-for-optinmonster\/","title":{"rendered":"How to enable Okta SSO and MFA for OptinMonster"},"content":{"rendered":"\n<p>Single sign-on (SSO) is a user authentication tool that enables users to securely access applications and services using just one trusted set of credentials. OptinMonster&#8217;s <a href=\"https:\/\/okta.com\">Okta<\/a> integration provides your business additional layers of controlling access to your OptinMonster account.<\/p>\n\n\n\n<div class=\"alert-box alert-blue\">\n<p class=\"alert-box-title\"><\/p>\n\n\n\n<p>OptinMonster&#8217;s Okta integration is an optional security solution. It is available only for Growth and Enterprise subscriptions, and includes a one-time implementation fee. If you&#8217;re interested in enabling Okta on your account, please <a href=\"https:\/\/optinmonster.com\/contact-us\/\">reach out to support<\/a> to learn more prior to completing the steps below.<\/p>\n\n\n\n<p class=\"is-style-arrow-link has-link-color\"><\/p>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Create a new application called OptinMonster<\/h2>\n\n\n\n<p>Once logged in to the Okta admin, navigate to the&nbsp;<strong>Applications<\/strong>&nbsp;page using the sidebar on the left.<br>Click the&nbsp;<strong>Create App Integration<\/strong>&nbsp;button.<br>In the resulting pop-up select&nbsp;<strong>SAML 2.0<\/strong>&nbsp;and click&nbsp;<strong>Next<\/strong>.<\/p>\n\n\n\n<p>On the&nbsp;<strong>Create SAML Integration<\/strong>&nbsp;page, enter the following:<br><em>*Any setting not directly addressed is optional.<\/em><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">General Settings<\/h2>\n\n\n\n<p><strong>App name:<\/strong>&nbsp;OptinMonster<br><strong>App logo:<\/strong>&nbsp;You can&nbsp;<a href=\"https:\/\/optinmonster.com\/presskit\">download our Press Kit here<\/a> \u2014 For best results, use the&nbsp;<code>Logos\/Web\/Logo\/logo-color-medium.png<\/code> file. This logo will help identify to your users that they are logging into OptinMonster via Okta.<\/p>\n\n\n\n<p>Click&nbsp;<strong>Next.<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Configure SAML<\/h2>\n\n\n\n<p><em>The <strong>&lt;slug&gt;<\/strong> referenced below will be provided as part of the setup with support.<\/em><\/p>\n\n\n\n<p><strong>Single Sign On URL:<\/strong>&nbsp;https:\/\/app.optinmonster.com\/saml\/sso\/<strong>&lt;slug&gt;<\/strong>\/<br>Ensure \u201c<em>Use this for Recipient URL and Destination URL<\/em>\u201d is checked<br><strong>Audience URI:<\/strong>&nbsp;https:\/\/app.optinmonster.com\/saml\/sso\/<strong>&lt;slug&gt;<\/strong>\/<br><strong>Default RelayState:<\/strong>&nbsp;no value<br><strong>Name ID Format:<\/strong>&nbsp;EmailAddress<br><strong>Application Username:<\/strong>&nbsp;Email<\/p>\n\n\n\n<p>Click&nbsp;<strong>Next.<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Feedback<\/h2>\n\n\n\n<p><strong>Are you a customer or partner?<\/strong>: Select&nbsp;<em>\u201cI\u2019m an Okta customer adding an internal app\u201d<\/em><br><strong>App type<\/strong>: Check&nbsp;<em>\u201cThis is an internal app that we have created\u201d<\/em><\/p>\n\n\n\n<p>Click&nbsp;<strong>Finish.<\/strong><\/p>\n\n\n\n<p>Once finished, you should be directed to your new application\u2019s page.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">(Optional) Setup Multifactor Authentication (MFA)<\/h2>\n\n\n\n<p>If you would like to implement MFA\/2FA with this Okta SSO setup, you will need to first ensure MFA methods are setup for your organization, and that in your policy, they are set as&nbsp;<strong>required<\/strong>. Configuring these settings is outside the scope of OptinMonster support. Please see Okta&#8217;s guides for implementing MFA below:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.okta.com\/resources\/whitepaper-multi-factor-authentication-deployment-guide\/\">https:\/\/www.okta.com\/resources\/whitepaper-multi-factor-authentication-deployment-guide\/<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/developer.okta.com\/docs\/guides\/mfa\/-\/main\/\">https:\/\/developer.okta.com\/docs\/guides\/mfa\/-\/main\/<\/a><\/li>\n<\/ul>\n\n\n\n<p>To ensure this SSO SAML 2.0 Application implements your MFA methods, you will need to add a new Sign On Policy Rule.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>On the application page, click on the&nbsp;<strong>Sign On<\/strong>&nbsp;tab<\/li>\n\n\n\n<li>Scroll down to the&nbsp;<strong>Sign On Policy<\/strong> section<\/li>\n\n\n\n<li>Click on the&nbsp;<strong>Add Rule<\/strong>&nbsp;button<\/li>\n\n\n\n<li>Give the rule a name, e.g.&nbsp;<strong>SSO MFA<\/strong><\/li>\n\n\n\n<li>For most of these settings, select the values most fitting for your application<\/li>\n\n\n\n<li>Ensure the&nbsp;<strong>Prompt for factor<\/strong> is checked, and select the frequency for the prompt<\/li>\n\n\n\n<li>Click&nbsp;<strong>Save<\/strong><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Collect and&nbsp;Send Application Information<\/h2>\n\n\n\n<p>To complete your setup, we need you to collect the following information for your app and send to support@optinmonster.com.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>On the application page, click on the&nbsp;<strong>Sign On<\/strong>&nbsp;tab<\/li>\n\n\n\n<li>In the sidebar, click on the&nbsp;<strong>View SAML setup instructions&nbsp;<\/strong>button<\/li>\n\n\n\n<li>A new tab should open titled&nbsp;<strong>How to Configure SAML 2.0 for OptinMonster Application<\/strong>.<\/li>\n\n\n\n<li>On this screen you should be presented with the following:<br>\u2013 Identity Provider Single Sign-On URL<br>\u2013 Identity Provider Issuer<br>\u2013 X.509 Certificate<\/li>\n<\/ol>\n\n\n\n<p>We suggest using <a href=\"https:\/\/secrets.supportally.com\/\" target=\"_blank\" rel=\"noopener nofollow\" title=\"\">https:\/\/secrets.supportally.com\/<\/a> to share this information with OptinMonster support.<\/p>\n\n\n\n<p>Once we\u2019ve received the information above, we will complete the integration for your account and let you know when it is complete.<\/p>\n\n\n\n<p>To test the completed OptinMonster Okta integration, visit your Okta account and click on the OptinMonster application. You should be immediately logged in through your Okta credentials. Alternatively, if any user logs in with an email ending with your configured domain, they will be redirected to the SSO login.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Single sign-on (SSO) is a user authentication tool that enables users to securely access applications and services using just one trusted set of credentials. OptinMonster&#8217;s Okta integration provides your business additional layers of controlling access to your OptinMonster account. Create a new application called OptinMonster Once logged in to the Okta admin, navigate to the&nbsp;Applications&nbsp;page&nbsp;&hellip;<\/p>\n","protected":false},"author":152,"comment_status":"open","ping_status":"closed","template":"","documentation\/categories":[214],"documentation\/tags":[32045,31459],"class_list":["post-185224","optinmonster_docs","type-optinmonster_docs","status-publish","hentry","categories-account-management"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/optinmonster.com\/wp-json\/wp\/v2\/documentation\/185224","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/optinmonster.com\/wp-json\/wp\/v2\/documentation"}],"about":[{"href":"https:\/\/optinmonster.com\/wp-json\/wp\/v2\/types\/optinmonster_docs"}],"author":[{"embeddable":true,"href":"https:\/\/optinmonster.com\/wp-json\/wp\/v2\/users\/152"}],"replies":[{"embeddable":true,"href":"https:\/\/optinmonster.com\/wp-json\/wp\/v2\/comments?post=185224"}],"version-history":[{"count":14,"href":"https:\/\/optinmonster.com\/wp-json\/wp\/v2\/documentation\/185224\/revisions"}],"predecessor-version":[{"id":205754,"href":"https:\/\/optinmonster.com\/wp-json\/wp\/v2\/documentation\/185224\/revisions\/205754"}],"wp:attachment":[{"href":"https:\/\/optinmonster.com\/wp-json\/wp\/v2\/media?parent=185224"}],"wp:term":[{"taxonomy":"categories","embeddable":true,"href":"https:\/\/optinmonster.com\/wp-json\/wp\/v2\/documentation\/categories?post=185224"},{"taxonomy":"internal_tags","embeddable":true,"href":"https:\/\/optinmonster.com\/wp-json\/wp\/v2\/documentation\/tags?post=185224"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}