Skip to main content

Setting up Okta SSO for your employees (SAML)

Written by Ben Team

Single sign-on (SSO) lets your employees log in to Ben with their normal company login instead of a separate Ben password — one less password to lose or reset, and it keeps sign-in within your organisation's own security controls.

This guide covers setting up SSO for Ben using Okta with SAML.

A note for admins

As the admin for your Ben portal, you may not be the person who sets up SSO — the steps below are technical and are usually handled by your organisation's IT or Security team. We recommend you send this article to them so they have what they need.

Once they've done the setup, you can let your employees know they can log in to Ben with SSO.

If you're weighing up SAML against OIDC, see SAML vs OIDC — but which one is right for your organisation is a decision for your IT or Security team.

Information for your IT or Security team

Requirements

  • Admin access to an Okta tenant

That’s it for requirements — you’ll set up the connection together with the Ben team by following the steps below.

Supported Features

  • IdP-initiated SSO

  • SP-initiated SSO

For more information on the listed features, visit the Okta Glossary.


Configuration Steps

⚠️ Enabling SAML will affect all users who use the Ben app.

Once it’s enabled, everyone at your company signs in to Ben through SAML. If you need to change this, contact Ben Support.

  1. In the Okta dashboard, navigate to Applications and then select the Applications sub-menu.

  2. Click on Browse App Catalog, search for Ben and add the application.

  3. Navigate to the Ben application. Go to the Sign On tab on, copy the Metadata URL and send it to the Ben team working on your implementation

  4. The Ben team will provide you will provide you with your unique Customer ID value.

  5. In Okta, select the Sign On tab for the Ben app, then click Edit.

    • Scroll down to Advanced Sign-on Settings.

    • Enter your Customer ID (step 4) into the corresponding field.

    • Click Save.

Congrats! You’ve set up Ben for Okta SSO.


SAML attributes

The required SAML claims are preconfigured in the marketplace app, but just in case you need them, we’ve compiled them in the table below:

Name

Value

email

user.email

given_name

user.firstName

family_name

user.lastName

SP-initiated SSO

  1. Enter your email address and click Continue

Ben icon

This is an icon you can use for the Ben app.

Did this answer your question?