<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Configure SAML authentication with Okta on Grafana Labs</title><link>https://grafana.com/docs/grafana/v12.4/setup-grafana/configure-access/configure-authentication/saml/configure-saml-with-okta/</link><description>Recent content in Configure SAML authentication with Okta on Grafana Labs</description><generator>Hugo -- gohugo.io</generator><language>en</language><atom:link href="/docs/grafana/v12.4/setup-grafana/configure-access/configure-authentication/saml/configure-saml-with-okta/index.xml" rel="self" type="application/rss+xml"/><item><title>Configure SAML with Okta catalog application</title><link>https://grafana.com/docs/grafana/v12.4/setup-grafana/configure-access/configure-authentication/saml/configure-saml-with-okta/oin-application/</link><pubDate>Fri, 03 Apr 2026 19:43:06 +0000</pubDate><guid>https://grafana.com/docs/grafana/v12.4/setup-grafana/configure-access/configure-authentication/saml/configure-saml-with-okta/oin-application/</guid><content><![CDATA[&lt;h1 id=&#34;configure-saml-with-okta-catalog-application&#34;&gt;Configure SAML with Okta catalog application&lt;/h1&gt;
&lt;p&gt;Grafana offers multiple ways to configure the SAML authentication flow. This guide focuses on configuring the authentication flow using the Okta Integration Network (OIN) application.&lt;/p&gt;
&lt;p&gt;The Grafana Labs application can be found in the &lt;a href=&#34;https://www.okta.com/integrations/&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;Okta Integration Network catalog&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id=&#34;prerequisites&#34;&gt;Prerequisites&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Grafana Enterprise or a paid Grafana Cloud account.&lt;/li&gt;
&lt;li&gt;Admin privileges in both Grafana and Okta.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;supported-features&#34;&gt;Supported features&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;SAML Single Sign-On (SSO)&lt;/li&gt;
&lt;li&gt;SAML Attribute Mapping&lt;/li&gt;
&lt;li&gt;SAML Group Mapping&lt;/li&gt;
&lt;li&gt;SAML External ID Mapping for SCIM provisioning&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;configure-saml-using-the-oin-application&#34;&gt;Configure SAML using the OIN application&lt;/h2&gt;
&lt;h3 id=&#34;at-the-okta-integration-network-catalog&#34;&gt;At the Okta Integration Network catalog&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Visit the &lt;a href=&#34;https://www.okta.com/integrations/&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;Okta Integration Network catalog&lt;/a&gt; and search for &lt;strong&gt;Grafana Labs&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Within the &lt;strong&gt;Grafana Labs&lt;/strong&gt; application page, click on &lt;strong&gt;&#43;Add Integration&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Select the tenant to add the integration to.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id=&#34;at-the-grafana-labs-application-page&#34;&gt;At the Grafana Labs application page&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;If needed, update the &lt;strong&gt;Application label&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Set the domain name. For example, &lt;code&gt;your-grafana-domain.grafana.net&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Click on &lt;strong&gt;Done&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;section class=&#34;expand-table-wrapper&#34;&gt;&lt;div class=&#34;button-div&#34;&gt;
      &lt;button class=&#34;expand-table-btn&#34;&gt;Expand table&lt;/button&gt;
    &lt;/div&gt;&lt;div class=&#34;responsive-table-wrapper&#34;&gt;
    &lt;table&gt;
      &lt;thead&gt;
          &lt;tr&gt;
              &lt;th&gt;Field&lt;/th&gt;
              &lt;th&gt;Description&lt;/th&gt;
          &lt;/tr&gt;
      &lt;/thead&gt;
      &lt;tbody&gt;
          &lt;tr&gt;
              &lt;td&gt;&lt;strong&gt;Application label&lt;/strong&gt;&lt;/td&gt;
              &lt;td&gt;The name of the application.&lt;/td&gt;
          &lt;/tr&gt;
          &lt;tr&gt;
              &lt;td&gt;&lt;strong&gt;Domain name&lt;/strong&gt;&lt;/td&gt;
              &lt;td&gt;The domain name of the Grafana instance.&lt;/td&gt;
          &lt;/tr&gt;
      &lt;/tbody&gt;
    &lt;/table&gt;
  &lt;/div&gt;
&lt;/section&gt;&lt;h3 id=&#34;at-the-grafana-labs-integration-page&#34;&gt;At the Grafana Labs Integration page&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;At the &lt;strong&gt;Assignments&lt;/strong&gt; tab, add the groups or users that should have access to the application.&lt;/li&gt;
&lt;li&gt;At the &lt;strong&gt;Sign On&lt;/strong&gt; tab, copy the &lt;em&gt;Metadata URL&lt;/em&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&#34;update-saml-configuration-at-grafana&#34;&gt;Update SAML configuration at Grafana&lt;/h2&gt;
&lt;h3 id=&#34;at-the-grafana-labs-saml-settings-page&#34;&gt;At the Grafana Labs SAML settings page&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Navigate to the &lt;strong&gt;SAML settings&lt;/strong&gt; page within the &lt;strong&gt;Authentication&lt;/strong&gt; section from the left-hand menu.&lt;/li&gt;
&lt;li&gt;The only required step is pasting the &lt;em&gt;Metadata URL&lt;/em&gt; in the &lt;strong&gt;IdP Metadata URL&lt;/strong&gt; field, located at the &lt;strong&gt;3. Connect Grafana with Identity Provider&lt;/strong&gt; tab.&lt;/li&gt;
&lt;li&gt;Save and apply the changes.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;With this configuration, the users will be able to access Grafana using their Okta credentials.&lt;/p&gt;
]]></content><description>&lt;h1 id="configure-saml-with-okta-catalog-application">Configure SAML with Okta catalog application&lt;/h1>
&lt;p>Grafana offers multiple ways to configure the SAML authentication flow. This guide focuses on configuring the authentication flow using the Okta Integration Network (OIN) application.&lt;/p></description></item></channel></rss>