Microsoft Defender for Cloud Apps
Architecture and deployment

Deploy conditional access app control for any web app using Okta

In brief

The article updates its metadata and clarifies setup instructions, including where the IdP SSO URL, signing certificate, Defender for Cloud Apps SSO URL, and attribute values are used in later steps.

What Defender admins need to know

Administrators configuring Okta can use the revised step references to locate the required values and certificate files.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Deploy conditional access app control for any web app using Okta as the identity provider (IdP)

Step 3: Create a new Okta Custom Application and App Single Sign-On configuration

  1. In the Okta Admin console, under Applications, view the properties of your existing configuration for your app, and make note of the settings.

    Screenshot of the Okta application Sign On tab showing the View Setup Instructions option and SSO service location.

  2. Make a note of the Identity Provider Single Sign-On URL and download the identity provider's Signing Certificate (X.509). You'll need both the URL and the signing certificate in Step 4 to configure Defender for Cloud Apps.

  3. Back in Salesforce, on the existing Okta single sign-on settings page, make a note of all the settings.

  4. Create a new SAML single sign-on configuration. Apart from the Entity ID value that must match the custom application's Audience URI (SP Entity ID), configure the single sign-on using the settings from the existing Okta single sign-on settings page noted in the previous step. You'll need this new configuration later when configuring Defender for Cloud Apps.

Provide Defender for Cloud Apps with your Okta identity provider details.

  1. In Defender for Cloud Apps, on the IDENTITY PROVIDER page, click Next to proceed.

  2. On the next page of the IDENTITY PROVIDER wizard, select Fill in data manually, do the following, and then click Next.

    • For the Single sign-on service URL, enter the Salesforce Login URL you noted earlier.

    Screenshot of Defender for Cloud Apps identity provider settings showing the SSO service URL and SAML certificate upload fields.

  3. On the External Configuration page, make a note of the following information, and then click Next. You'll need the Defender for Cloud Apps single sign-on URL and attribute values when configuring the Okta custom application in Step 5.

    • Defender for Cloud Apps single sign-on URL
    • Defender for Cloud Apps attributes and values
![Screenshot of the Defender for Cloud Apps configuration page showing the SSO URL and attribute values.](media/proxy-idp-okta/idp-okta-cas-get-sf-app-external-config.png)
![Screenshot of the Defender for Cloud Apps configuration page showing the SSO URL and attribute values.](media/proxy-idp-okta/idp-okta-cas-get-sf-app-external-config.png)