> Source: [sk183448](https://support.checkpoint.com/results/sk/sk183448)

# sk183448 - How to configure Okta SSO for ERM

| Property | Value |
|----------|-------|
| Solution ID | sk183448 |
| Date Created | 2025-05-11 |
| Last Modified | 2025-05-11 |
| Technical Level | General |
| Products | External Risk Management |
| Versions | Cloud |

## Solution

This document outlines the process required to integrate Okta with Argos ERM for the purpose of authentication.   

**General Okta authentication setup steps**

* Define and configure custom app integration using OIDC within Okta.
* Provide the relevant integration details to ERM for back-office setup of the integration within ERM.
* **\<Optionally\>** If additional users are required on top of those currently defined -- a list of those additional users and their roles should be provided to ERM (authentication will automatically take place through Okta).

**Defining and configuring a custom app integration within Okta** Below is a four-step process to configure Okta to integrate with Argos ERM.  

The instructions of each step are followed with a screenshot for the Okta user interface showing the resulting configuration for that step.  

**Step 1 -- Create a new App integration**

* Open the okta admin panel.
* In the sidebar click "Applications"-\>" Applications".
* In the righthand pane, click the Create App Integration button.

<br />

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1746792546613/UntitWWled202505091414372.png)  

<br />

* In the Sign-in method section choose OIDC -- OpenID Connect.
* For Applications type choose Web Application
* Click Next.

<br />

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1746792546613/UntitWWled202505091416393.png)  

<br />

<br />

**Step 2 -- Define application General settings**   

* In the App integration name box type 'Argos ERM'
* Under Grant Type, check the Refresh Token and the Implicit (hybrid) boxes.
* In the Sign-in redirect URIs box, type https://\[ENVIRONMENT_DNS\]/authentication/callback
* Press Save

**NOTE:** Environment DNS refers to the Argos ERM URL. e.g https://tenantname.cyberint.io  

<br />

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1746792546613/UntitWWled202505091419134.png)  

<br />

**Step 3 -- Edit the General settings**   

* Press on the edit button on the General settings.
* Under APPLICATION -\> Grant type, uncheck Allow Access Token with implicit grant type.
* Under USER CONSENT -\> User consent, uncheck Require consent.
* Under Login-\> Initiate login URI box, type
  * https://\[ENVIRONMENT_DNS\]/api/v1/authentication/init/\[TEAM_ID\]
* Press on the save button

**NOTE:** Team ID refers to the environment name that can be found on ERM General settings, generally it should contain no spaces, if unsure you may reach to your admin.  

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1746792546613/UntitWWled202505091422575.png)  

<br />

**Step 4 -- Send Integration details to ERM** (CSM or Sales engineer or your admin)  

For ERM to complete the integration on their side, the following information must be sent to the customer success team, or the dedicated analyst.  

In case the environment is self managed, please navigate to Settings by clicking on the COG Icon on the left panel and selecting "SSO Configuration"  

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1746792546613/UntitWWled202505091426486.png)  

The following information is needed from Okta side:

* Client ID
* Client secret
* OpenID configuration URI/Metadata URI
* Okta client domain URI

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1746792546613/Screenshot 2025-05-09 142809202505091428237.jpg)  

**Setting up additional users within ERM to authenticate through Okta (Optional)** After the above steps are completed, all the existing users within ERM will be authenticated through Okta, is necessary to make sure that the user intended to log in with OKTA has SSO enabled or enforced.  

This can be set under General settings -\> User management.  
After selecting the user you will see the option to choose the login method.  

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1746792546613/UntitWWled202505091431298.png)  

If additional users are to be configured, the usernames for those users need to be sent to ERM, along with their appropriate role (operational/executive). All new users defined will automatically authenticate through Okta.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
