The BizLibrary integration with Okta enables admin to take advantage of several features.
Create Users:
Users who have not already been created in BizLibrary will be created upon application assignment. Once a user is assigned, the user is created and is able to log in, once the update time has passed.
Update User Attributes:
User attributes can be updated from Okta to BizLibrary by changing attributes of assigned users. These user attributes will be stored and updated in BizLibrary.
Deactivate Users:
Users who are unassigned from BizLibrary within Okta will be deactivated in BizLibrary. Deactivated users do not count towards your licensed user allotment.
Push Groups:
Currently, BizLibrary supports pushing groups to BizLibrary from Okta. At the moment, the groups are only stored. In the future, SCIM groups will likely be used as an attribute for the team rule engine.
Add BizLibrary to Your Applications
On your Okta console, go to Application > Applications > and click Browse App Catalog.
Search for BizLibrary.
Select BizLibrary, then choose Add.
On the following screen, review your settings and click Done.
Set up SAML on your Okta Application
Your next step is to configure SAML on your Okta application, in order to enable Single Sign on. First, head to BizLibrary, and go to the administration section. From here, click the admin menu and navigate to
System > Authentication:
Click “New Authentication Method”, and name it “Okta”, or something else that you’ll remember. Doing this will present you with some data:
On BizLibrary, add an Authentication Method Title (Can be any string - “Okta” is recommended.) Add an IDP Name of “Okta”
Add the IDP Authentication Request Endpoint, which you can find in Okta. To find it, go to the Sign On tab and click Setup SAML Instructions in your Okta console.
- Then in the default RelayState, add https://lms.bizlibrary.com/learner
- IDP Authentication Request Endpoint: *
You’ll see the endpoint on the next page:
Copy this URL and paste it into IDP Authentication Request Endpoint: * on BizLibrary:
Choose your Authentication Context Class Reference. We see that unspecified is the most common selection for integrating with Okta.
The last item within BizLibrary is to map your assertion attributes. At least one field needs to be mapped. We recommend mapping email to username, or another mapping that makes sense for your organization.
Enter the mapping and click “Add.”
Once finished populating these fields, you are good to save.
Setting up SAML From Okta
The last step to set up SAML is to configure your Identity Provider, Okta.
Go to Applications → Applications, select your BizLibrary app, then navigate to Sign On → SAML Settings, and click Edit.
You should see this screen:
Your information should look like the screenshot above. Please note that you may need to manually populate the Attribute Statements as shown above.
In the audience URI, copy and paste your entity ID from the Authentication page inside BizLibrary:
Then in the default RelayState, add https://lms.bizlibrary.com/learner
Your configuration should be complete!
Enable SCIM Provisioning
The last step is to enable provisioning. To do this, inside Okta, head to Applications > BizLibrary App > Provisioning tab click Configure API Integration
Now, you’ll have a Provisioning tab inside your BizLibrary Okta application. In your unique identifier field, we recommend choosing “userName”.
You can choose any supported action, except for importing groups. For authentication mode, choose HTTP Header.
Now, you’ll need to reach out to your BizLibrary Client Success Manager to receive a secure token, and your SCIM base URL..
Once you’ve done this, you are ready to start provisioning users!
Note: User provisioning can take anywhere from 20 minutes to several hours. The duration depends on the size of your directory and the number of users in scope for provisioning.
Update time
If you do not see the intended updates in 24 hours, please reach out to your BizLibrary Client Success Manager.