Overview
Using Okta as an Identity Provider, administrators can allow users to sign in directly to the Managed Services Center.
Keep the following information handy
ACS URL:
https://login.druva.com/api/commonlogin/mspsamlconsumeAudience URI (Entity ID):MSC-login
Procedure
Step 1: Launch Okta to select the sign-in method
In the Okta Admin Console, go to Applications > Applications.
Click Create App Integration.
Select SAML 2.0 as the Sign-in method.
Click Next.
Step 2: Configure General Settings
Specify the name of your app. You can use any name.
Add a logo for your app (optional).
If you want to hide your app from your users' homepage, select the App visibility checkbox (optional).
Step 3: Configure SAML General settings
Provide the Single Sign-on URL (Copy the ACS URL given in the overview section).
Provide the Entity ID (Copy the Entity ID given in the overview section).
Select the Email Address from the drop-down lists of formats for the Name ID format.
Step 4: Configure the SSO token obtained from Managed Services Center:
Generate and copy the SSO token from Managed Services Center.
Navigate to the OKTA Application, and go to Configure SAML tab. Under the Attribute Statements (Optional) section, enter the following attributes:
Name:druva_auth_token
Value:Paste SSO token generated in MSC
Click Next.
Step 5: Select the option to configure Druva MSC in Okta
Select I'm a software vendor. I'd like to integrate my app with Okta.
Click Finish. Your integration is created in your Okta org.
Step 6: Assign the MSC app to administrators (users)
Select the MSC app and go to the Assignment tab.
Click the Assign button from the top-left corner, and then select Assign to People from the drop-down list.
Search for administrators and click the Assign button available in front of that administrator.
If you want to change the user name, edit it and then click the Save and Go back button.
Note: The username should match the email address used for MSC Administrators.Click Done to complete the action.
Step 7: Get IdP login URL and Certificate
To update the Single Sign-on settings in the Managed Services Center
Copy the IdP login URL and certificate from Okta.
Go to Managed Services Center and paste the IdP login URL and certificate in the appropriate fields.
(Optional) SAML Authentication requests and encrypt assertions
The AuthnRequests Signed and Encrypt assertions are optional settings in Managed Services Center. If you want to add more security to your SSO, you can enable these settings.
Procedure
Step 1: Enable Security Settings and Retrieve Your SAML Certificate
Log in to the Managed Services Center.
Navigate to Settings > Access Settings.
In the Single Sign-On (SSO) section, click Configure SSO (for first-time setup) or Edit.
Under ID Provider Configuration, select the AuthnRequests Signed or Encrypt Assertions checkbox.
While still in this window, copy the SAML certificate and save it to your computer in
.crtformat.Click Save to apply your changes in Druva.
Finally, upload the
.crtfile to your Identity Provider (IdP).
❗ Important
This certificate will be the same for both AuthnRequests Signed and Encrypt Assertions.
Step 2: Upload SSO SAML Certificate to IdP
Copy the SSO SAML Druva certificate provided above and save it in a .crt format.
Navigate to the OKTA Application, search and select the application from the list.
In the General tab, edit the SAML settings.
Click Next, and then click Show Advanced Settings in the Configure SAML tab.
Change “Assertion Encryption” from Unencrypted to Encrypted.
Click Browse files for the Encryption Certificate, and then select the saved SSO SAML Druva certificate.
Click the Next button, and then click Finish on the feedback tab to complete the update.

