Single Sign-On FAQ

These answers cover common questions about single sign-on (SSO) and SCIM provisioning in Oktopost.

What is the difference between SSO and SCIM?

SSO controls how users authenticate into Oktopost. SCIM controls how users are created, updated, and deactivated in Oktopost from your identity provider. You can use SSO without SCIM, but SCIM requires a SAML application configured in your IdP.

Do I need the Single Sign-On add-on?

Yes. SSO and SCIM require the Single Sign-On add-on on your Oktopost license. Reach out to your account manager if SSO is not available in your account settings.

What ACS URL and Entity ID should I use?

For US-hosted accounts, the ACS URL is https://app.oktopost.com/auth/acs. The Entity ID is usually https://app.oktopost.com for Microsoft Entra ID, Google Workspace, PingIdentity, and AD FS. Okta custom apps typically use urn:oktopost:sp. EU-hosted accounts use the same paths with an eu- prefix (for example, https://eu-app.oktopost.com/auth/acs).

Can I use one SSO configuration for both Oktopost and the Advocacy board?

Yes. Oktopost supports one SSO configuration per account. The same SAML setup can authenticate users to both the platform and the Advocacy board. For IdP-initiated sign-in through Okta, set Default Relay State to 1 for platform users or 2 for board users.

Can I provision platform users and advocates through the same SCIM app?

No. Choose one SCIM endpoint per enterprise application: https://app.oktopost.com/scim/v2 for platform users or https://board.oktopost.com/scim/v2 for advocates. Create separate IdP applications if you need both.

Why does SCIM provisioning fail when Username and Email differ?

Oktopost requires the SCIM userName value and the work email address to match. Map both fields to the same source attribute in your IdP, such as mail or userPrincipalName.

What happens when I enable Require SSO?

All users must sign in through SSO, including advocates once they update the mobile app to version 2.3.5 or higher. Password-based sign-in and two-factor authentication in Oktopost are disabled for required SSO accounts. Add at least one user to the exclusion list before enabling Require SSO.

Can I exclude a user from SSO for only the platform or only the board?

No. If a user has access to both Oktopost and the Advocacy board, an SSO exclusion applies to both applications.

Where do I sign in for SP-initiated SSO?

Go to https://app.oktopost.com/auth/login-sso, enter your SSO email address, and click Sign in. EU-hosted accounts use https://eu-app.oktopost.com/auth/login-sso.

Was this article helpful?
0 out of 0 found this helpful