Configuring user roles based on Okta Single Sign-On responses in Arctera Insight Management Console

Article: 100073334
Last Published: 2025-01-27
Ratings: 0 0
Product(s): eDiscovery Platform, Veritas Alta eDiscovery

Prerequisites

Select Role Management > Authentication Management and ensure the Role-Based Claims option is enabled for the customer. If it is not already enabled, enable it.

Procedure

To Configure Role-Based Claims

  1. In the Okta SSO app, configure role mapping to send built-in or custom administration role names (without spaces) to the approle string array attribute in the SAML response. To achieve this, navigate to Profile EditorOkta Alta SSO App (Veritas SSO User) and add a string array attribute to the user profile. Refer to the sample screenshots below:


  2. Map the required role names (defined in Manage) to the string array attribute created earlier. Do this by providing the values during user assignment to the app or by editing the user profile for the app to include these values.

    Roles defined in Manage


    Providing the values during user assignment to the app




    Or, editing the user profile for the app to add these values

  3. Update attribute mapping in the Okta SSO app by navigating to Applications → SSO App (Veritas SSO).

  4. Edit the app configuration to map the user profile attribute to the approle SAML response attribute.




  5. Verify the configuration by ensuring the SAML response after SSO login includes the role names in the approle attribute. Confirm that the account role user in Manage receives the corresponding roles sent in the SAML response.

    Account Role user

SSO login for the user

 

 

Was this content helpful?