Jump to content

Moiz V

Members
  • Posts

    10
  • Joined

  • Last visited

Posts posted by Moiz V

  1. On 3/18/2021 at 12:03 PM, jtstuedle said:

    Using Okta as a SAML provider for PasswordState. Setup was smooth and easy (happy to provide a quick write-up on this if someone wants to publish it on the site). Upon login via the SAML provider, I'm getting a NameID attribute wasn't found in the PasswordState database.

     

    I've searched some forums and looked through system settings but don't see any option to "automatically create SAML user if the account does not exist" (or something to that effect). Other applications call this something like "just-in-time provisioning". Does Passwordstate have this feature? If not, feature request?

     

    Error I'm getting back from Passwordstate: It appears your account has successfully authenticated to the SAML Identity Provider, but the NameID attribute returned was not found in the Passwordstate database. Obviously I can create this user in the Database, but with a large number of users this seems counter-intuitive to just auto-creating upon login from the identity provider.

     

    If Okta is just a SAML provider and on-prem AD is the identity source, you can just enable the feature to auto-create AD accounts in PasswordState when you sync Security Groups? The user should be able to login after an Okta delta-sync runs.

     

    Otherwise, if Okta is the identity source, this is probably a feature request since it'd require some sort of custom connector with Okta via their API.

×
×
  • Create New...