Skip to main content

Single Sign-On from the Okta Dashboard

Boxphish SSO Setup Guide (Okta Dashboard). Okta has been integrated with Boxphish via OIDC flow. The login is initiated by clicking on the Okta tile within the customer’s Okta dashboard. Once the log…

Neil Davies
Updated by Neil Davies

Boxphish SSO Setup Guide (Okta Dashboard)

Okta has been integrated with Boxphish via OIDC flow. The login is initiated by clicking on the Okta tile within the customer’s Okta dashboard.

Once the login is initiated from Okta (the tile is clicked) a URL is hit in Boxphish (https://portal.boxphish.com/oktasso_initiate), with the Okta domain (Issuer URL) and Client ID parameters identifying which customer’s Okta instance initiated the login. Boxphish validates this issuer is tied to a Boxphish tenancy, and if yes the remaining OIDC flow is triggered where Okta returns its token to Boxphish.

We implicitly trust those tokens so if the email account that launched the application in Okta matches an email account in the applicable tenancy in Boxphish the user will be logged in.

This guide explains how to set up Single Sign-On (SSO) between Okta and Boxphish using OpenID Connect (OIDC). It is written for customers and IT administrators who manage Okta.

What You’ll Need

  • Okta Administrator access and knowledge of creating Okta dashboard tiles
  • A Boxphish tenant

Step 1: Open Applications in Okta

  1. Sign in to your Okta Admin Console
  2. From the left-hand menu, select Applications
  3. Click Create App Integration

Step 2: Create a New App Integration

  1. When prompted to choose a sign-in method: Select OIDC – OpenID Connect
  2. Choose Single Page Application
  3. App integration name: Boxphish SSO
  4. Ensure Authorization Code is selected
  5. Click Advanced and Select Implicit (hybrid)
  6. Add the following Sign‑in redirect URI: https://portal.boxphish.com/oktasso
  7. Assign Users to the Application
    1. Allow everyone in your organisation to access or
    2. Limit access to selected groups -> create a group for Boxphish users and add users to that group
  8. Click Save.

After saving, remain on the application page.

  1. Go to the General tab
  2. Click Edit under General Settings
    1. Uncheck Allow Access Token with implicit grant type
    2. Uncheck Require consent
  3. Select Login initiated by: Either Okta or App
  4. Tick Display application icon to users
  5. Login flow: Redirect to app to initiate login (OIDC Compliant)
  6. Initiate login URI: https://portal.boxphish.com/oktasso_initiate  (for prod)
  7. Click save

Step 4: Validate Setup

Your Okta application for Boxphish SSO is now configured. After setup, please provide the following to the Boxphish team and they will enable the integration:

  • Client ID from the Okta application.
  • Okta domain (Issuer URL) e.g. https://<company_ID>.okta.com

Once Boxphish has confirmed that this is configured you will be able validate launching and logging in from the Okta Dashboard.

How did we do?

Managing your User Sync

De-Duplication of Courses and Simulations

Contact