Configuring Okta Workforce Identity Cloud
This section describes the steps to be performed in the Okta Workforce Identity Cloud administration to register the Central NAC application and provide access to the Okta Workforce Identity Cloud instance.
To configure Okta Workforce Identity Cloud as an identity provider, you must install the following applications:
Cloud Auth OIDC
To install the Cloud Auth OIDC application, complete the following steps:
-
Log in to the Okta Workforce Identity Cloud administration console.
-
Navigate to the Applications tab and click Applications.
-
Click Browse App Catalog.
-
Select OIDC in the Functionality section.
-
Search for Cloud Auth OIDC and select the Cloud Auth OIDC application.
-
Select Add Integration and click Done.
-
Select Sign On.
-
In the Settings section select Edit.
-
Scroll down to the Advanced Sign-on Settings.
-
Copy the Redirect URI obtained from the Central NAC identity store and paste it in the Redirect URI field which is located above the help text. For more information, see Copy Redirect URI.
-
In the Credentials Details section, for Application username format, select Email.
-
Click Save.
For the Cloud Auth OIDC application to authenticate a user, the user must be assigned the application. For more information about how users are assigned to applications, see https://help.okta.com/en-us/content/topics/users-groups-profiles/usgp-assign-apps.htm.
Cloud Auth API Service
To install the Cloud Auth API Service application, complete the following steps:
-
Log in to the Okta Workforce Identity Cloud administration console.
-
Navigate to the Applications tab and click Applications.
-
Click Browse App Catalog.
-
Select API in the Functionality section.
-
Search for Cloud Auth API Service and select the Cloud Auth API Service application.
-
Select Add Integration.
-
Select Install & Authorize.
The Client Secret is displayed. Copy this as the Service Client Secret.
-
Click Done.
The Client ID is displayed. Copy this as the Service Client ID.
APIs for Okta Workforce Identity Cloud
The following Okta core APIs are used by Central NAC to authorize users in Okta Workforce Identity Cloud: