Configure SSO Just-in-time Provisioning for Okta in Prisma Cloud
0
Created On 06/14/19 15:20 PM - Last Modified 07/19/22 23:14 PM
Objective
Configure SSO Just-in-time Provisioning for Okta
Environment
Prisma Cloud configured with SSO (Okta)
Procedure
Note: This is done with Okta Classic UI
- Configure SSO w/ Okta without using the built-in Prisma Cloud App.
- Within Okta, create a custom attribute on the Prisma Cloud Okta App
- Go to Directory -> Profile Editor
- Under Filters, click on "App"
- Find the Prisma Cloud app and click on "Profile"
- Click "Add Attribute"
- Display name - whatever you like
- Variable name - "rrole" (or any value you like)
- Attribute length - make sure it's long enough to fit the Prisma Cloud Role name/
- Configure Attribute Statements on the Prisma Cloud Okta App
- Go to Applications -> Applications
- Click on the Prisma Cloud application
- Go to General tab
- Click on Edit next to SAML Settings
- Go to Step 2
- Under Attribute Statements (Optional), add these:
- Configure Prisma Cloud Role attribute for each of the users
- Go to Applications -> Applications
- Click on the Prisma Cloud application
- Go to Assignments tab
- For existing users
- Click on the pencil icon
- Add the Prisma Cloud Role you want to give this user (e.g. "System Admin")
- For new users
- Click on Assign -> Assign to People
- Click "Assign" for the user you want to give access to Prisma Cloud
- Define the Prisma Cloud Role you want to give this user (e.g. "System Admin")
- Configure Prisma Cloud for SSO JIT
- Login to Prisma Cloud
- Go to Settings -> SSO
- Under JIT section, enter these values:
(Notice that the values match to the Attribute Statement Names in Step 3.f)
- Run a test by logging in with a user that is assigned to the Prisma Cloud application in Okta