Documentation Index

Fetch the complete documentation index at: https://docs.workspot.com/llms.txt

Use this file to discover all available pages before exploring further.

Okta Authentication for Workspot Control

Prev Next

Okta can be used as a Workspot Identity Provider (IdP) by configuring Okta as a SAML 2.0 Service Provider in Workspot Control. This allows the Workspot Control administrator to single sign-on into Control through the Okta web portal.

Prerequisites and Configuration Notes

The following are general prerequisites for this guide:

  • Okta administrator login.

  • Workspot Control administrator login.

We will perform configuration first in the Okta administrator’s portal, then in Workspot Control.

Okta Configuration for Workspot Control

This section outlines the steps to add and configure the Workspot Control app into the Okta web portal.  

  1. Sign into the Okta administrator console.

  2. Click “Add Application > Create New Application.”

  3. Select “SAML 2.0” and then “Create.”

  1. In “App name,” enter “Workspot Control,” then click “Next.”

  1. In “SAML Settings,” enter the following into “Single sign-on URL”: https://customeridentifier.workspot.com/saml/assertion, using the your Workspot Customer Identifier in the “customeridentifier” field.

  2. Similarly, enter the following into “Audience URI”: https://customeridentifier.workspot.com/saml/metadata.

  3. Click “Download Okta Certificate.”

    1. Save this Okta certificate for use when configuring Workspot Control.

    2. Rename the file from “okta.cert” to “okta.crt.”

  4. Click “Show Advanced Settings.”

  1. “Under Advanced Settings”, set the “Assertion Encryption” to “Encrypted.”

  2. Download the Workspot Encryption Certificate from: https://download.workspot.com/workspotstar.crt.

    1. Note: This is a Workspot certificate and not the Okta certificate downloaded in the previous step.

    2. Back in the Okta Administrator Console, use “Browse files…” to upload the Workspot certificate to Okta.

  1. In the “Attribute Statements (Optional)” section, enter the Name “emailaddress” and select “user.email” from the “Value” dropdown. Click “Next” and then on the next screen click “Finish.”

  1. On the “Sign On” tab, click “View Setup Instructions.”

  1. Copy and save the “Identity Provider Single Sign-on URL” and “Identity Provider Issuer” URL.

  1. Assign the Workspot Control app to the user or group. For more information, see the Assign Applications section of Okta’s Access and customize app integrations page.

Workspot Control Configuration for Okta

Once the Okta configuration is complete, use a Control Administrator’s account to sign-in to the Workspot Control site, https://control.workspot.com.

  1. Go to “Setup > SAML.”

  2. For the “Entity ID,” paste the “Identity Provider Single Issuer URL” from step 13 above.

  3. Similarly, for the “Signon Service URL,” paste the Identity Provider Single Sign-on URL.

  4. For the Logout Service URL, enter https://youroktadomain.okta.com/login/default where “youroktadomain.okta.com” is the domain which you use to login to Okta.

  5. Then click “Choose File” and upload the Okta certificate okta.crt from step 7, above.

Testing the Configuration

To test the configuration,

  1. Sign into the Okta web portal

  2. From the portal, click on the Workspot Control icon.

After a signing in page, the Control dashboard will be displayed.