Skip to content
English
  • There are no suggestions because the search field is empty.

Setting up Okta SSO for Pequity

Before we start off, here are a couple of reminders to ensure that you will be able to successfully enable Okta SSO:

  • You’ll need to have an Okta account to setup the Okta SSO in Pequity.
  • You must be an Okta administrator to make application configurations in Okta.
  • You must be a Pequity administrator to make site-wide configurations in Pequity. This is something the Pequity team will handle on your behalf.

 

Configure Pequity Application in Okta

In Okta, navigate to Applications > Applications and select Create App Integration.

Screenshot 2023-09-06 at 4.42.48 AM.png

 

Select the SAML 2.0 for the Sign-in method. Select Next.

Screenshot 2023-09-06 at 4.43.24 AM.png

In the General Settings, add “Pequity” as the App name. You can download the App logo here. Leave the App visibility selections unchecked, and select Next to continue.

Screenshot 2023-09-06 at 4.44.14 AM.png

In Configure SAML, fill out the SAML Settings.

Please note, as stated below, “company” in the URLs throughout this document should be replaced with the company name of your instance. For example “Walmart.pequity.app,” not “Company.pequity.app”

📣 Please note that this URI URL should NOT have a trailing slash. This is intentional. If a trailing slash is added to this link, the setup will not work.
  • Default RelayState will be left blank.
  • Name ID format will be EmailAddress.
  • Application username will be Okta Username.
  • Update application username on will be Create and update.

Screenshot 2023-09-06 at 4.49.34 AM.png

 

Next, add 3 Attribute Statements (optional). This will map Pequity user data to Okta user data.

  • first_name will be attributed to the value user.firstName.
  • last_name will be attributed to the value user.lastName.
  • email will be attributed to the value user.email.

Screenshot 2023-09-06 at 4.50.24 AM.png

Leave the Group Attribute Statements (optional) blank. We’ll walk through how to add Pequity to specific user groups in the next section.

Next, select Preview SAML Assertion. Save this file and send it to your Pequity Customer Success Manager and Pequity Technical Project Manager.

Screenshot 2023-09-06 at 4.51.00 AM.png

Finally, in the Feedback section, select that you are an Okta customer, scroll to the bottom of the page and select Finish.

Screenshot 2023-09-06 at 4.51.30 AM.png

 

Create a Pequity user group in Okta

This is optional if you’d like to restrict Pequity access to specific users in a group.

In Okta, navigate to Directory > Groups and select Add Group.

Screenshot 2023-09-06 at 4.52.07 AM.png

Enter the group name and description (we recommend adding the term  “Pequity” to the name and description), and select Save.

Screenshot 2023-09-06 at 4.52.33 AM.png

Within the Pequity group, navigate to the Applications tab and select Assign applications.

Screenshot 2023-09-06 at 4.53.04 AM.png

Find the Pequity application and select Assign and then Done.

Screenshot 2023-09-06 at 4.53.41 AM.png

Then, navigate to the People tab in the Pequity group and select people to assign to the group.

Screenshot 2023-09-06 at 4.55.12 AM.png

📣 Important information on User Access:

  1. If an existing user logs into Pequity using Okta with an email that does not match their Pequity user email, they will be created as a new user and their Pequity permissions will not transfer.
  2. For new users logging into Pequity but granted access to Pequity in Okta, they will default to “guests” until a company admin specifies their permissions.

 

Configure Okta in Pequity

Navigate to Applications and select Pequity. On the General tab, select Edit within SAML Settings.

Screenshot 2023-09-06 at 4.56.47 AM.png

Select Next in the General Settings to land on Configure SAML. On the far-right of the page, Select Download Okta Certificate.

Screenshot 2023-09-06 at 5.00.11 AM.png

Then, scroll down to the section titled Preview the SAML assertion generated from the information above, select Preview SAML Assertion

Screenshot 2023-09-06 at 5.00.39 AM.png

Save both the Okta Certificate as well the SAML Assertion.


Please also navigate to the Sign On tab. Scroll down until you see the link for "identity provider metadata. Once you click the "identity provider metadata" link, it will open up a new tab with the code. Please download this code to XML. This has the entity ID in it which is required to finalize setup.

Screenshot 2023-09-06 at 5.01.08 AM.png

Send the Okta Certificate, SAML Assertion, and Identity Provider Metadata to your Pequity Customer Success Manager and Pequity Technical Project Manager to finalize the Okta setup within Pequity.

 

Congratulations! You’ve setup Okta with Pequity 🎉

 

Logging into Pequity with SSO & Provisioning

Pequity supports JIT provisioning by automatically creating a new account in Pequity when they initially open the Pequity app via SSO but were not previously added as Pequity users. We currently don’t support SCIM - all comp-related permissioning lives in Pequity once the account is created.

When a user is removed from your IDP, they would also have to be removed from Pequity. Once a user has been removed from your IDP but still remains in Pequity, they still will not be able to access the tool since they would need IDP log in. Here’s our documentation to help with this.