/ /

Configuring OneLogin for SSO

Updated 4 months ago

Note: You must have an account with admin privileges in OneLogin to complete this setup.

Overview

This guide walks you through configuring OneLogin as a SAML Identity Provider for Osano. You will use the SAML Custom Connector (Advanced) application template, set up the required parameters, and provide metadata to Osano Support.

Step-by-Step Setup

1. Log in to OneLogin

  • Log in to your OneLogin admin portal.

2. Add a New Application

  • Click Applications in the top menu.

  • Click Add App.

    • In the search bar, type SAML Custom Connector (Advanced) and select it from the results.

  • In the App Name field, enter a name (e.g., Osano).

  • Click Save.

3. Configure SAML Settings

  • Go to the Configuration tab.

  • Enter the following values:

    • RelayState:

      • https://my.osano.com/sign-in/

    • Audience (EntityID):

      • urn:amazon:cognito:sp:us-east-1_7GtagkRKw

    • Recipient:

      • https://auth.osano.com/saml2/idpresponse

    • ACS (Consumer) URL Validator:

      • https://auth.osano.com/saml2/idpresponse

    • ACS (Consumer) URL:

      • https://auth.osano.com/saml2/idpresponse

4. Add Custom Parameters

  • Go to the Parameters tab.

  • Click the Plus button to create a new custom parameter.

  • Create two parameters:

    • Field name: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress

    • Field name: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name

  • For Value on both, select Email from the dropdown.

  • For Flags, check Include in SAML assertion.

5. Save and Assign Users

  • Click Save to apply your changes.

  • Assign users or groups who should have access to Osano.

6. Provide Metadata to Osano

  • Under the More Actions dropdown, select SAML Metadata.

  • Provide this metadata document to Osano Support.

7. Osano Finalizes Setup

  • Osano will configure these settings for your account and confirm when the connection is established.

8. Test SSO Login

  • Navigate to my.osano.com and enter your email address.

  • You should be redirected to your organization’s SSO login page.

Accessing Osano from the OneLogin Portal (Bookmark App)

Note: Osano does not currently support IdP-initiated logins. If you want users to access Osano directly from the OneLogin applications page, you should create a Bookmark app.

To create a Bookmark app in OneLogin:

  1. Log in to OneLogin and go to Applications > Applications.

  2. Click Add App and search for Bookmark. Select Shortcut from the results.

  3. Enter a name for the app (e.g., "Osano").

  4. Ensure the application is set as Visible in Portal and click Save.

  5. In the left menu, go to Configuration and add https://my.osano.com as the Website Address. Click Save.

  6. Assign users or groups who should have access to Osano to the Bookmark app.

  7. Hide the original SAML app in the portal so users only see the Bookmark app.

Was this article helpful?
Subscribe to receive updates on this article