> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/content-collections/administration/setup-sso-integration-on-prisma-cloud/get-started-with-saml-sso/setup-sso-integration-on-prisma-cloud-for-okta.md).

# Set up Okta SSO on Prisma Cloud

To secure administrator access to Prisma Cloud, go to Okta to configure single sign-on and then configure Prisma Cloud for SSO.

On Prisma Cloud, you can enable single sign-on (SSO) using Okta. To enable SSO, you must first complete the setup on Okta. You can then log in with System Administrator privilege on the Prisma Cloud administrator console to configure SSO and redirect login requests to the Okta login page so that your Prisma Cloud administrative users can log in using SSO.

If you do not want to set up SSO for your administrative users who need to log in to Prisma Cloud, but need instructions for ingesting SSO data for the effective permissions calculation in the IAM Security module, see [Integrate Prisma Cloud with Okta](https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/administration/administration/configure-iam-security/integrate-prisma-cloud-with-okta.md).

To avoid account lockout, you must enable a few administrative users with both local authentication credentials on Prisma Cloud and SSO access. Ensure that each administrator has activated their Palo Alto Networks Customer Support Portal (CSP) account using the Welcome to Palo Alto Networks Support email and set a password to access the portal.

1. Set up Okta for SSO.
   1. Before you begin to set up Okta configuration, login to your Prisma Cloud instance and copy the Audience URI (SP Entity ID) from Prisma Cloud. See For example: <https://app.prismacloud.io/settings/sso>.
   2. Login to Okta as an Administrator and click **Admin**.

      <figure><img src="/files/0maixxduFj5OzCBqqOzO" alt="sso okta admin"><figcaption></figcaption></figure>
   3. Click **Add Applications**.

      <figure><img src="/files/ZEYpZQ7zKrxd0CffFLLb" alt="sso okta add application"><figcaption></figcaption></figure>
   4. **+Add Apps** to create a new app.

      <figure><img src="/files/IXh1lp0A317QWZXQTikm" alt="sso okta create new app"><figcaption></figcaption></figure>
   5. On **Create a New Application Integration**, select **Web** for **Platform** and **SAML 2.0** for **Sign on method**.

      <figure><img src="/files/l1AG4sfqtQWCG43K9WYU" alt="sso okta saml web"><figcaption></figcaption></figure>
   6. Click **Create**.
   7. On **General Settings**, use these values and click **Next**.

      **App Name** - Prisma Cloud SSO app

      **App Logo** - Use the Prisma Cloud logo

      **App Visibility** - Do not check these options

      <figure><img src="/files/P5mDCD5YHZs4Xl6cHtB9" alt="sso okta general settings"><figcaption></figcaption></figure>
   8. To **Configure SAML**, specify the **Sign On URL**.

      The format for Sign On URL uses the URL for Prisma Cloud, but you must replace app with api and add saml at the end. For example, if you access Prisma Cloud at <https://app2.prismacloud.io>, your Sign On URL should be userinput:\[<https://api2.prismacloud.io/saml>] and if it is <https://app.eu.prismacloud.io>, it should be userinput:\[<https://api.eu.prismacloud.io/saml>] .
   9. For **Audience URI** - Use the value displayed on Prisma Cloud **Settings > Access Control > SSO** that you copied in the first step.
   10. Select **Name ID format** as **Persistent** and **Application username** as **Okta username**.

       The value for the Name ID format must be set to persistent so that your IdP sends the same unique value for the NameID element in all SAML requests from a particular user. If you set it to anything else, the user will have a different saml:sub value for each session, and is not secure.

       <figure><img src="/files/LOReHajIeLQdqB1EbGuZ" alt="sso okta create saml integration"><figcaption></figcaption></figure>
   11. Set **Update application username** to **Create and update**.
   12. For **Advanced Section**, select **Response** as **Unsigned**, **Assertion Signature** as **Signed**, **Assertion Encryption** as **UnEncrypted**.

       These options ensure that the SAML authentication message are digitally signed by the IDP, and it restricts login to the SAML app only from browsers that have the signed certificate.
   13. tt:\[(Required only for JIT provisioning of a local user account automatically on Prisma Cloud)] Specify the attributes to send with the SAML assertion.

       For more details, see [Set up Just-in-Time Provisioning on Okta](/content-collections/administration/setup-sso-integration-on-prisma-cloud/get-started-with-saml-sso/set-up-jit-on-okta.md). If you want to assign groups, you should define a filter Matches regex with Value = (.\*) to match against all groups.

       <figure><img src="/files/M2cLcgsIpjiag4L8u1KD" alt="sso okta attribute statements"><figcaption></figcaption></figure>
   14. Finish creating the app.

       You have now successfully created an application for the SAML integration. This application will have the details of the **IdP URL** and **Certificate** which you’ll need to add on Prisma Cloud to complete the SSO integration.
   15. Assign users or groups of users who can use the Prisma Cloud SSO app to log in to Prisma Cloud.

       Select Assignments on the app and **Assign > Assign to People**, to add individual users.

       <figure><img src="/files/P2iybkVQheTURhwwsVYa" alt="sso okta assign users"><figcaption></figcaption></figure>

       You can also **Assign to Groups**, to specify the groups to which your users are assigned. Groups are evaluated top down, which means users will be assigned to the first group in the order.

       <figure><img src="/files/khTlTJqy8toVcpjzdNB4" alt="sso okta assign groups"><figcaption></figcaption></figure>
   16. tt:\[(Required only for JIT provisioning of a local user account automatically on Prisma Cloud)]Assign the role you created on Prisma Cloud to the user profile.
2. Configure SSO on Prisma Cloud.
   1. Log in to Prisma Cloud and select **Settings > Access Control > SSO**.
   2. **Enable SSO**.
   3. Enter the value for your **Identity Provider Issuer**.

      This is the URL of a trusted provider such as Google, Salesforce, Okta, or Ping who act as your IdP in the authentication flow. On Okta, for example, you can find the Identity Provider issuer URL at **Applications > Sign On > View Setup Instructions**.

      <figure><img src="/files/JUEDLWWgccxSgIxjRzEC" alt="sso get idp for prisma cloud"><figcaption></figcaption></figure>

      In the setup instructions, you have Identity Provider Issuer and Prisma Cloud Access SAML URL.
   4. Enter the **Identity Provider Logout URL** to which a user is redirected to, when Prisma Cloud times out or when the user logs out.
   5. Enter your IdP **Certificate** in the standard X.509 format.

      You must copy and paste this from your IdP.

      <figure><img src="/files/BkEVK5D7gvfIzA0PPG5Z" alt="sso okta certificate"><figcaption></figcaption></figure>
   6. Enter the **Prisma Cloud Access SAML URL** configured in your IdP settings.

      For example, on Okta this is the Identity Provider Single Sign-On URL. When you click this URL, after authentication with your IdP, you are redirected to Prisma Cloud. This link along with the Relay State Parameter is used for all the redirection links embedded in notifications like email, slack, SQS, and compliance reports.
   7. **Relay State Param name** is SAML specific Relay State parameter name. If you provide this parameter along with Prisma Cloud Access SAML URL, all notification links in Splunk, Slack, SQS, email, and reports can link directly to the Prisma Cloud application. The relay state parameter or value is specific to your Identity Provider. For example, this value is userinput:\[RelayState] for Okta.

      When using RelayState functionality, make sure your Prisma Cloud Access SAML URL corresponds to Identity Provider Single Sign-On URL ending in ‘/sso/saml’.
   8. tt:\[(Optional)] Clear the **Enforce DNS Resolution for Prisma Cloud Access SAML URL**.

      By default, Prisma Cloud performs a DNS look up to resolve the Prisma Cloud SAML Access URL you entered earlier. If your IdP is on your internal network, and you do not need to perform a DNS look up, you can clear this option to bypass the DNS lookup.
   9. tt:\[(Optional)]Enable Just-in-Time Provisioning for SSO users.

      **Enable JIT Provisioning**, if you want to create a local account for users who are authenticated by the IdP. With JIT, the user is provisioned with the first five roles mapped to the user’s profile on the IdP.
   10. Provide the user attributes in the SAML assertion or claim that Prisma Cloud can use to create the local user account.

       You must provide the email, role, first name, and last name for each user. Timezone is optional.

       <figure><img src="/files/z3FPlDnq1AWj00CScN4S" alt="sso okta prisma cloud attribute statements"><figcaption></figcaption></figure>

       The role that you specify for the user’s profile on the IdP must match what you created on Prisma Cloud in Step 1.
   11. Select **Allow select users to authenticate directly with Prisma Cloud** to configure some users to access Prisma Cloud directly using their email address and password registered with Prisma Cloud, in addition to logging in via the SSO provider.

       When you enable SSO, make sure to select a few users who can also access Prisma Cloud directly using the email and password that is registered locally on Prisma Cloud to ensure that you are not locked out of the console in the event you have misconfigured SSO and need to modify the IdP settings. For accessing data through APIs, you need to authenticate directly to Prisma Cloud.
   12. Select the **Users** who can access Prisma Cloud either using local authentication credentials on Prisma Cloud or using SSO.

       The users listed in the allow list can log in using SSO and also using a local account username and password that you have created on Prisma Cloud.

       <figure><img src="/files/cfWunjpWI4AWGSKmqXsz" alt="sso users excluded"><figcaption></figcaption></figure>
   13. **Save** your changes.
   14. Verify access using SSO.

       Administrative users for whom you have enabled SSO, must access Prisma Cloud from the Identity Provider’s portal. For example, if you have integrated Prisma Cloud with Okta, administrative users must login to Okta and then click on the Prisma Cloud app icon to be logged in to Prisma Cloud.
   15. Using **View last SSO login failures**, you can see details of last five login issues or errors for SSO authentication for any users.

       <figure><img src="/files/Diz5wXNtGnnkTWOOb7Ho" alt="sso last five errors 1"><figcaption></figcaption></figure>

       If the user is logged in already using a username/password and then logs in using SSO, the authentication token in the browser’s local storage is replaced with the latest token.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/content-collections/administration/setup-sso-integration-on-prisma-cloud/get-started-with-saml-sso/setup-sso-integration-on-prisma-cloud-for-okta.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
