Configure Single Sign-On (SSO) with Okta
This article will cover how to set up single sign-on (SSO) using SAML 2.0 in Okta for your Muck Rack instance. SSO will allow your licensed Muck Rack users to access the Muck Rack application securely using their Okta credentials.
Supported SAML Features
The Muck Rack app that is part of the Okta Integration Network (OIN) currently supports
the following features:
SP-initiated SSO
Requirements
To set up SSO for your Muck Rack instance, you will need:
Approval from your Muck Rack account executive or your Muck Rack customer success manager
An Okta account with an Application Administrator or a Super Administrator role assigned.
You must use the same email address for both your Okta account and your Muck Rack account
Installing the Muck Rack OIN App
In a new browser window, sign in to your Okta Admin dashboard using an Okta account that has Super Administrator or Application Administrator privileges.
Navigate to your Okta Admin sidebar and select Applications > Applications.
Next, select the Browse App Catalog button in the Applications window.
In the search bar, search for “Muck Rack” and select the Muck Rack app from the search results and then select the Add Integration button in the top right corner of the app description window.
Because Muck Rack does not support IdP-initiated SSO, check the box that says:
Do not display application icon to users; this will help minimize login errors by preventing users from signing in via their Okta dashboard.
Select the Done button to continue to the SAML configuration.
Configuring SAML Settings
Contact the Muck Rack support team at support@muckrack.com and request that they enable SAML 2.0 for your account.
Once you receive a SAML Setup Instructions email from Muck Rack Support with your connection name, navigate to the Sign On tab of your Muck Rack app.
Select Edit to the right of the Settings heading and navigate to the SAML 2.0 section.
Select Attributes (Optional) to expand the section.
Add the following SAML claims to the Attribute statements (Optional) section:
Email
Attribute name:
email
Attribute value:
user.email
Name format:
Unspecified
First name
Attribute name:
given_name
Attribute value:
user.firstName
Name format:
Unspecified
Last name
Navigate down to the Advanced Sign-on Settings section.
Add the connection name provided to you in your SAML Setup Instructions email to
the Connection name field.
Note: This is typically the subdomain for your Muck Rack instance, e.g. your orgname in https://[org-name].muckrack.com
Select Email from the Application username format drop-down menu.
Select the Save button to save your SAML settings.
Setting up SSO to Test
Navigate to the Assignments tab of your Muck Rack app and add the users
that will need access to Muck Rack; you will use these users to test SSO.
Then, navigate to the Sign on methods section of your Muck Rack app and
copy the Metadata URL.
Reply to the SAML Setup Instructions email that Muck Rack Support sent and
paste the metadata URL in the message.
Once you receive an email from Muck Rack Support confirming that your
connection is ready to test, open an incognito or a private browser window and
go to: https://muckrack.com/login/sso
Enter the email address you use for Okta and select the Log In button.
You will be redirected to your Okta sign-on page.
Enter your Okta login credentials and authenticate using MFA (if applicable).
You should now be logged in to your Muck Rack account; if you run into an
issue signing in, please contact support@muckrack.com for assistance.
Once you’ve successfully completed testing, please send a reply in your thread
with Muck Rack Support confirming that you’d like SSO hard-enabled.
All of your active Muck Rack users will be force logged-out of the Muck Rack
app and be asked to sign in with SSO on their next visit.
Get Help
For additional help, contact support by choosing the chat icon in the bottom right-hand corner of the screen and selecting Messages > Send us a message.
💬 Was this article helpful?
Share your feedback and let us know how to improve our Help Center content.