This article contains instructions for configuring single sign-on (SSO) for your KCM GRC platform with Okta. When you enable SSO for KCM GRC, your users can log in to your platform without creating a password.
To complete the instructions below, you must be an account administrator in both KCM GRC and Okta.
Jump to:Add the KCM GRC Platform to OktaConfigure Okta SSO in KCM GRCTest SSO Integration
Add the KCM GRC Application to Okta
Before configuring SSO in your KCM GRC platform, connect KCM GRC to your Okta account by following the instructions below.
First, add the KCM GRC application to your Okta account.
- Log in to Okta.
- Navigate to the Applications tab.
- Click the Add Application button.
- Type "KCM GRC Platform" in the search bar.
- Select KCM GRC Platform.
- Click the Add button.
Next, obtain your KCM GRC subdomain so you can add it to the Subdomain field in Okta.
- Open the KCM GRC platform in a new window or tab.
- Log in to your KCM GRC account.
- In the top-right corner of the screen, navigate to Settings > Account Settings.
- Click the SSO Settings tab on the View Account page.
- Copy your subdomain from the Sign in URL field.
- The subdomain is between "https://" and "kb4compliance.com". For example, if your Sign in URL is "https://organization.kb4compliance.com/saml/login", your subdomain is "organization".
Finally, continue configuring SSO in Okta.
- Return to the General Settings page in Okta.
- Paste your subdomain into the Subdomain field.
- Click Next.
- Click the Identity Provider metadata link below the View Setup Instructions button. By clicking this link, an Okta metadata XML file will be downloaded to your device. You will need to import this file into your KCM GRC account to finish the configuration.
- Click Done.
Configure Okta SSO in KCM GRC
After you add the KCM GRC application to Okta, follow the instructions below to configure SSO with Okta in KCM GRC.
- Log in to your KCM GRC account.
- In the top-right corner of the screen, navigate to Settings > Account Settings.
- Click the SSO Settings tab on the View Account page.
- Click the SSO Enabled toggle to enable SSO.
- Click the Upload SSO Metadata button in the SSO Provider Config area.
- Select the Identity Provider metadata XML file that you downloaded in step 15 of the section above.
- Wait for the file to import successfully.
- Select Okta from the SSO Provider drop-down menu.
- Click Save in the bottom-left corner.
Note:As a precaution, Account Administrators will retain the ability to log in to KCM GRC with their password.
Test SSO Integration
After you configure SSO in KCM GRC, we recommend that you test your SSO integration by following the steps below.
- Log in to your KCM GRC account.
- In the top-right corner of the screen, navigate to Settings > Account Settings.
- Click the SSO Settings tab on the View Account page.
- Click the Test SSO Configuration button.
- Click Continue in the SAML Integration Test window.
After you click Continue, a window will open to indicate whether the SSO configuration was successful. If the configuration was successful and you are logged in to Okta with the same email address that you use for KCM GRC, this window will redirect you to your KCM GRC dashboard.
If the configuration was unsuccessful, this window will redirect you to a "Page not found" error screen. Review the instructions in this article to verify that you configured SSO correctly in Okta and KCM GRC. Then, if you still encounter the error, please contact the KCM GRC support team.