In this SAML SSO setup, Okta manages your organization's user accounts and credentials, and links with Blinq as the service provider for those users. Security Assertion Markup Language (SAML) is a security standard for managing authentication and access. When you enable SSO with Blinq, the login prompt for your team changes to only allow SSO.
What you'll need
A Blinq Enterprise subscription
Owner access to your Blinq account
Okta Admin access
Both Blinq and Okta open in separate browser tabs
How enforced SAML SSO works
Your team attempts to log in to Blinq via SAML SSO.
Blinq sends a SAML request to Okta.
They are redirected to the Okta login page to complete login.
Okta checks your team member's credentials.
Okta sends a response to Blinq to verify the team member's identity.
Blinq accepts the response and logs the team member into their Blinq account.
Note: Blinq uses SAML 2.0 for all SAML SSO configurations. This includes configurations with supported identity providers and any custom configurations.
Step 1: Confirm domains with Blinq Support
Enforced SSO means team members logging in with an email address from your selected domains are prompted to sign in via SSO. Team members can only join your workspace if their email address ends in one of your validated domains. You can list more than one domain, including subdomains.
Contact Blinq Support and send a list of the domains you want to register for SSO, including an example email address for each.
Blinq approves the domains and confirms you can continue to configuration.
You may be required to validate that you own each domain name via DNS verification.
Note: You can request to add or remove domains for your organization at any time by contacting Blinq Support.
Step 2: Open Security in Blinq
Log in to the dashboard as your Blinq account Owner.
Select the Workspace menu in the top left corner.
Open Security from the settings menu. Keep this tab open while you work, you'll need to copy information between Blinq and Okta in both directions.
Step 3: Configure SSO in Okta
Open Okta's Admin Dashboard.
Select the Applications menu, then Applications.
Select the blue Create App Integration button.
Select SAML 2.0 from the integration options, then select Next.
The Create SAML Integration screen opens. Under General Settings, create an App Name. You can choose whatever makes sense to your team, and upload a logo if you'd like.
Select Next and proceed to step 2, Configure SAML.
Copy the ACS URL from Blinq Security and paste it into the Single sign on URL field in Okta.
Copy the Service provider app entity ID from Blinq Security and paste it into the Audience URI (SP Entity ID) field.
Leave the Default RelayState field blank.
Select email address for the Name ID format.
Select Okta username as the Application username.
Select create & update to update the application username.
No other attributes are required by Blinq, so select Next.
Select Customer for the question "Are you a customer or partner", then select Finish.
You should land on the application settings page for the app you just created. If not, select the Blinq application from the list of Applications.
From the Application settings screen, select the Sign On tab, then expand More details within the SAML 2.0 box.
Select Copy to copy the Sign on URL from Okta, and paste the value into the Identity Provider Entity ID field in Blinq Security.
Select Copy to copy the Issuer from Okta, and paste the value into the Identity Provider Entity ID (Issuer Entity ID) field in Blinq Security.
Select Copy to copy the Signing Certificate from Okta, and paste it directly into the Certificate field in Blinq Security with no additional formatting.
Step 4: Enable SSO in Blinq
Navigate back to the Security settings in your dashboard.
Toggle on Enforce SSO for all users.
Your SSO is now configured for your organization. All users logging in with email addresses ending in your domain are directed to log in using SSO.
Log out of Blinq. When you log back in, you should be taken through the Okta SSO flow.
Need help?
Reach out via the chat widget in the Help Center or email [email protected].
