> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sonderplan.com/llms.txt
> Use this file to discover all available pages before exploring further.

# SAML Single Sign-On (SSO)

> Verwalten Sie die Integration von SAML Single Sign-On (SSO) für sicheren und nahtlosen Benutzerzugriff.

## Was ist SAML?

Security Assertion Markup Language (SAML, ausgesprochen SAM-el) ist ein offener Standard zum Austausch von Authentifizierungs- und Autorisierungsdaten zwischen Parteien, insbesondere zwischen einem Identitätsanbieter und einem Dienstanbieter.

In nicht-fachsprachlicher Sprache ermöglicht SAML SSO (Single Sign-On) Ihren Benutzern, sich bei Sonderplan (dem Dienstanbieter) mit Identitätsanbietern von Drittanbietern wie Google Workspace, Okta, Azure Active Directory und Onelogin anzumelden.

<Check>SAML SSO steht allen unseren Kunden zur Verfügung, und wir empfehlen, es zu implementieren, um die Sicherheitslage Ihres Unternehmens zu stärken.</Check>

SAML reduziert die Reibung und ermöglicht es Ihren Benutzern, auf Sonderplan mit ihrem bestehenden unternehmensgesteuerten Benutzerkonto zuzugreifen.

Die Implementierung von SAML bringt auch Vorteile für die IT-Administratoren Ihres Unternehmens mit sich, da der Verwaltungsaufwand reduziert und die Sicherheit durch die Zentralisierung von Benutzerkonten verbessert wird. SAML ist nicht nur für große Unternehmen gedacht, sondern wird für jedes Unternehmen empfohlen, das bereits ein zentrales Benutzerverzeichnis wie Google Workspace betreibt.

## Aktivierung von SAML SSO

Um SAML SSO zu aktivieren, gehen Sie zu **Admin -> Systemeinstellungen**, klicken Sie auf das **SAML Sign On (SSO) Einstellungen**-Accordion und ändern Sie dann die Option **Enable SAML SSO** auf **Aktiviert**.

<div className="rounded-video">
  <video autoPlay muted loop playsInline className="w-full not-prose" src="https://mintcdn.com/sonderplan-b228cb35/AlTcSS4AzTYvuSH-/videos/system/Sonderplan-SAML-SSO-Enable.mp4?fit=max&auto=format&n=AlTcSS4AzTYvuSH-&q=85&s=a20479ec549dfc2d7313508801cb474e" data-path="videos/system/Sonderplan-SAML-SSO-Enable.mp4" />
</div>

### Details des Identitätsanbieters

Diese Einstellungen werden von Ihrem Identitätsanbieter bereitgestellt, z. B. Google Workspace, Microsoft Azure Active Directory usw. Kopieren Sie diese bitte in die entsprechenden Felder und beachten Sie die Anleitungen weiter unten, wie Sie SAML in Ihrem Identitätsanbieter konfigurieren können.

#### Name des Identitätsanbieters

Dieses Feld wird auf der SSO-Anmeldeschaltfläche auf dem Anmeldebildschirm angezeigt.

#### IDP-Entity-ID / Issuer-URL

Identitätsanbieter-Issuer-Entity-ID, oft eine URL, z. B. [http://okta.com/Eksj7Hhsk24klljsd](http://okta.com/Eksj7Hhsk24klljsd)

#### IDP-Login-URL / SSO-Endpunkt

Die URL, die Sonderplan aufruft, um eine Benutzeranmeldung vom Identitätsanbieter anzufordern.

#### IDP-Logout-URL / SLO-Endpunkt

Die URL, die Sonderplan aufruft, um eine Benutzerabmeldung beim Identitätsanbieter anzufordern.

#### IDP X.509-Zertifikat

Das Authentifizierungszertifikat, das von Ihrem Identitätsanbieter ausgestellt wurde.

## Konfigurationsanleitungen

Diese Anleitungen behandeln die gängigsten Identitätsanbieter, die unsere Kunden verwenden. Wenn Sie jedoch auf Probleme stoßen oder Hilfe bei der Konfiguration eines anderen Anbieters benötigen, wenden Sie sich bitte an unser Support-Team.

### Google Workspace

Um Sonderplan SAML SSO mit Google Workspace zu konfigurieren, erweitern Sie bitte und befolgen Sie die Anweisungen in jeder Sektion:

<AccordionGroup>
  <Accordion title="1. Create new Google Workspace SAML app">
    1. Login to the Google Workspace Admin Console and navigate to **Apps -> Web and mobile apps**.
    2. Click **Add app -> Add custom SAML app**
           <img src="https://mintcdn.com/sonderplan-b228cb35/COGNuOeevCLC_Y0F/images/admin/saml-sso/google-workspace/google-workspace-saml-page-1.png?fit=max&auto=format&n=COGNuOeevCLC_Y0F&q=85&s=2ea03bb64d93e99a12d80540890a18e2" alt="Google Workspace Admin Console SAML setup page 1 screenshot" width="1201" height="933" data-path="images/admin/saml-sso/google-workspace/google-workspace-saml-page-1.png" />
    3. In **App details** enter ***Sonderplan*** as the **App name**, with a **Description** of ***Resource scheduling platform***
    4. Upload the App Icon which you can save from here:
           <img src="https://mintcdn.com/sonderplan-b228cb35/hbMdFMPsN5n2tQkr/images/icon/Sonderplan-Square-Icon.png?fit=max&auto=format&n=hbMdFMPsN5n2tQkr&q=85&s=55737a8d24cf5fd4b20df168df4847d4" height="150" width="150" alt="Sonderplan App Icon" data-path="images/icon/Sonderplan-Square-Icon.png" />
    5. Click **Continue**
  </Accordion>

  <Accordion title="2. Copy Google Workspace details into Sonderplan">
    <img src="https://mintcdn.com/sonderplan-b228cb35/COGNuOeevCLC_Y0F/images/admin/saml-sso/google-workspace/google-workspace-saml-page-2.png?fit=max&auto=format&n=COGNuOeevCLC_Y0F&q=85&s=ff6c1d0377cd789b89c04b5db69d8d0c" alt="Google Workspace Admin Console SAML setup page 2 screenshot" width="1210" height="1055" data-path="images/admin/saml-sso/google-workspace/google-workspace-saml-page-2.png" />

    1. In Sonderplan, head over to **Admin -> System Settings** and expand the **SAML Single Sign On (SSO)** settings panel
    2. Enable SAML SSO and enter ***Google Workspace*** as the **Identity Provider Name**
    3. Copy the **SSO URL** from Google Workspace to -> **Identity Provider Login URL / SSO Endpoint** AND **Identity Provider Logout URL / SLO Endpoint** in Sonderplan
    4. Copy the **Entity ID** from Google Workspace to -> **Identity Provider Entity ID / Issuer URL** in Sonderplan
    5. Copy the **Certificate** from Google Workspace to -> **Identity Provider X.509 Certificate** in Sonderplan
    6. Click **Save Changes** in the top right corner of Sonderplan
    7. In Google Workspace, click **Continue**

    <img src="https://mintcdn.com/sonderplan-b228cb35/COGNuOeevCLC_Y0F/images/admin/saml-sso/google-workspace/sonderplan-idp-settings.png?fit=max&auto=format&n=COGNuOeevCLC_Y0F&q=85&s=e2fdc36281e2d06861086cf152fbef2f" alt="Sonderplan SAML IDP Settings screenshot" width="1080" height="1117" data-path="images/admin/saml-sso/google-workspace/sonderplan-idp-settings.png" />
  </Accordion>

  <Accordion title="3. Enter Service Provider details into Google Workspace">
    <img src="https://mintcdn.com/sonderplan-b228cb35/COGNuOeevCLC_Y0F/images/admin/saml-sso/google-workspace/google-workspace-saml-page-3.png?fit=max&auto=format&n=COGNuOeevCLC_Y0F&q=85&s=cfd8a7fec9b8db2a37cca8580b673def" alt="Google Workspace Admin Console SAML setup page 3 screenshot" width="1234" height="1083" data-path="images/admin/saml-sso/google-workspace/google-workspace-saml-page-3.png" />

    1. Copy the **Recipient / ACS (Consumer) URL** from Sonderplan to -> **ACS URL** in Google Workspace Admin Console
    2. Copy the **Entity ID / Audience / Metadata URL** from Sonderplan to  -> **Entity ID** in Google Workspace Admin Console
    3. Make sure **Name ID** in Google Workspace Admin Console is set to **Basic information > Primary Email**
    4. Click **Continue**
  </Accordion>

  <Accordion title="4. SAML attribute mapping for Google Workspace">
    <img src="https://mintcdn.com/sonderplan-b228cb35/COGNuOeevCLC_Y0F/images/admin/saml-sso/google-workspace/google-workspace-saml-page-4.png?fit=max&auto=format&n=COGNuOeevCLC_Y0F&q=85&s=388961c9919265e427f80cc3ddb58d0f" alt="Google Workspace Admin Console SAML setup page 4 screenshot" width="1244" height="1140" data-path="images/admin/saml-sso/google-workspace/google-workspace-saml-page-4.png" />

    1. Configure the mapping of Google Directory attributes to the attributes of Sonderplan. Please refer to the screenshot above or table below.
       \| Google Directory attributes        | App attributes |
       \|------------------------------------|----------------|
       \| Basic Information -> Primary email | User.email     |
       \| Basic Information -> First name    | User.firstName |
       \| Basic Information -> Last name     | User.lastName  |
    2. Click **Finish**
  </Accordion>

  <Accordion title="5. Enabling SAML for Google Workspace Users">
    Once the app has been created, you'll need to enable the SAML app for your Google Workspace users.

    <img src="https://mintcdn.com/sonderplan-b228cb35/COGNuOeevCLC_Y0F/images/admin/saml-sso/google-workspace/google-workspace-saml-app-user-access.png?fit=max&auto=format&n=COGNuOeevCLC_Y0F&q=85&s=3b13d8c8d1b5f712206ed959d1cce1c3" alt="Google Workspace Admin Console SAML app user access" width="1426" height="762" data-path="images/admin/saml-sso/google-workspace/google-workspace-saml-app-user-access.png" />

    1. In the **Google Workspace Admin Console** navigate to **Apps -> Web and mobile apps -> Sonderplan -> User Access** change the access setting to **ON for everyone**
    2. Finally, you'll need to configure [your users in Sonderplan for SSO](/admin/saml-sso-settings#configure-users-for-sso)
  </Accordion>
</AccordionGroup>

### Microsoft Entra

Um Sonderplan SAML SSO mit Microsoft Entra zu konfigurieren, erweitern Sie bitte und befolgen Sie die Anweisungen in jeder Sektion:

<AccordionGroup>
  <Accordion title="1. Create new Entra Enterprise Application">
    1. Login to the Microsoft Azure Portal and navigate to **your directory -> Enterprise Applications -> All applications -> New application**
           <img src="https://mintcdn.com/sonderplan-b228cb35/COGNuOeevCLC_Y0F/images/admin/saml-sso/microsoft-entra/microsoft-entra-new-app.png?fit=max&auto=format&n=COGNuOeevCLC_Y0F&q=85&s=378d6d1732a612ea8de107ae707a20f1" alt="Microsoft Azure Portal create new enterprise application" width="1189" height="678" data-path="images/admin/saml-sso/microsoft-entra/microsoft-entra-new-app.png" />
    2. In the Microsoft Entra Gallery, click **Create your own Application**
           <img src="https://mintcdn.com/sonderplan-b228cb35/COGNuOeevCLC_Y0F/images/admin/saml-sso/microsoft-entra/microsoft-entra-create-own-application.png?fit=max&auto=format&n=COGNuOeevCLC_Y0F&q=85&s=8a5dc6d5bc2202ebfebc221c5a1b1dee" alt="Microsoft Azure Portal create own SAML app" width="1150" height="685" data-path="images/admin/saml-sso/microsoft-entra/microsoft-entra-create-own-application.png" />
    3. Enter ***Sonderplan*** as the name of the app
    4. Check that the option *Integrate any other application you don't find in the gallery (Non-gallery)* is selected
    5. Click **Create**
  </Accordion>

  <Accordion title="2. Enter Service Provider details into Entra">
    <img src="https://mintcdn.com/sonderplan-b228cb35/COGNuOeevCLC_Y0F/images/admin/saml-sso/microsoft-entra/microsoft-entra-configure-saml.png?fit=max&auto=format&n=COGNuOeevCLC_Y0F&q=85&s=f96f49ea1bf1d4c2f27f407fcbace545" alt="Microsoft Azure Portal configure saml sso" width="1149" height="784" data-path="images/admin/saml-sso/microsoft-entra/microsoft-entra-configure-saml.png" />

    1. In the newly created app *Sonderplan* app, expand the **Manage** section, then click **Single sign-on -> SAML**
    2. On the next screen, in the *Basic SAML Configuration*, click **Edit**

    <img src="https://mintcdn.com/sonderplan-b228cb35/COGNuOeevCLC_Y0F/images/admin/saml-sso/microsoft-entra/microsoft-entra-saml-step-1.png?fit=max&auto=format&n=COGNuOeevCLC_Y0F&q=85&s=38e6d79dcf14c6e9f6187e46663f9c8a" alt="Microsoft Azure Portal configure saml step one" width="1149" height="857" data-path="images/admin/saml-sso/microsoft-entra/microsoft-entra-saml-step-1.png" />

    3. In another window, open Sonderplan and head over to **Admin -> System Settings** and expand the **SAML Single Sign On (SSO)** settings panel
    4. Enable SAML SSO and enter ***Microsoft Entra*** as the **Identity Provider Name** then scroll down to the "*2. Service Provider Details (Sonderplan)*" section

    <img src="https://mintcdn.com/sonderplan-b228cb35/hbMdFMPsN5n2tQkr/images/admin/saml-sso/microsoft-entra/sonderplan-sp-copy-settings.png?fit=max&auto=format&n=hbMdFMPsN5n2tQkr&q=85&s=74f6bd76b205b8962d5732c997ca05c3" alt="Sonderplan SAML SSO copy settings for identity provider" width="1254" height="1783" data-path="images/admin/saml-sso/microsoft-entra/sonderplan-sp-copy-settings.png" />

    5. Copy the **Entity ID / Audience / Metadata URL** from Sonderplan to  -> **Identifier Entity ID** in the Azure SAML configuration
    6. Copy the **Recipient / ACS (Consumer) URL** from Sonderplan to -> **Reply URL (Assertion Consumer URL)** in the Azure SAML configuration
    7. Copy the **Single Logout URL** from Sonderplan to -> \*\*Logout Url (Optional) in the Azure SAML configuration
    8. Finally click **Save** at the top of the *Basic SAML Configuration* screen in the Azure Portal, then click the **x** in the top right corner

    <img src="https://mintcdn.com/sonderplan-b228cb35/COGNuOeevCLC_Y0F/images/admin/saml-sso/microsoft-entra/microsoft-entra-saml-step-2.png?fit=max&auto=format&n=COGNuOeevCLC_Y0F&q=85&s=3b85fcdf5c99b721f8c320feaff98ee5" alt="Microsoft Azure Portal configure saml step one" width="1130" height="1046" data-path="images/admin/saml-sso/microsoft-entra/microsoft-entra-saml-step-2.png" />
  </Accordion>

  <Accordion title="3. Copy Entra details into Sonderplan">
    <img src="https://mintcdn.com/sonderplan-b228cb35/COGNuOeevCLC_Y0F/images/admin/saml-sso/microsoft-entra/microsoft-entra-saml-step-3.png?fit=max&auto=format&n=COGNuOeevCLC_Y0F&q=85&s=fb2509f1a63fc94af49dd90a8e2132f5" alt="Microsoft Azure Portal configure saml sso" width="1134" height="1141" data-path="images/admin/saml-sso/microsoft-entra/microsoft-entra-saml-step-3.png" />

    1. Still in the Azure Portal, but back on the *SAML-based Sign-on* page for the Sonderplan Enterprise app, scroll down to section **3 SAML Certificates**
    2. Download the **Certificate (Base64)**, open the **Sonderplan.cer** file in a text editor on your computer and copy the entire contents of the file into the **Identity Provider X.509 Certificate** in the Sonderplan SAML SSO settings textarea
    3. Copy the **Login URL** from the Azure Portal to -> **Identity Provider Login URL / SSO Endpoint** in Sonderplan
    4. Copy the **Microsoft Entra Identifier** from the Azure Portal to -> **Identity Provider Entity ID / Issuer URL** in Sonderplan
    5. Copy the **Logout URL** from the Azure Portal to -> **Identity Provider Logout URL / SLO Endpoint** in Sonderplan
    6. Click **Save Changes** in the top right corner of Sonderplan

    <img src="https://mintcdn.com/sonderplan-b228cb35/hbMdFMPsN5n2tQkr/images/admin/saml-sso/microsoft-entra/sonderplan-idp-copy-settings.png?fit=max&auto=format&n=hbMdFMPsN5n2tQkr&q=85&s=4cfdd58f391b1fc8cbf7224feb1bdc40" alt="Sonderplan SAML SSO copy settings for identity provider" width="1032" height="1239" data-path="images/admin/saml-sso/microsoft-entra/sonderplan-idp-copy-settings.png" />
  </Accordion>

  <Accordion title="4. SAML Attribute Mapping for Entra">
    <img src="https://mintcdn.com/sonderplan-b228cb35/COGNuOeevCLC_Y0F/images/admin/saml-sso/microsoft-entra/microsoft-entra-saml-mapping.png?fit=max&auto=format&n=COGNuOeevCLC_Y0F&q=85&s=3dec35d5abfc119da6f7f8d6111ef168" alt="Microsoft Azure Portal configure saml sso" width="1187" height="970" data-path="images/admin/saml-sso/microsoft-entra/microsoft-entra-saml-mapping.png" />

    1. Still in the Azure Portal, but back on the *SAML-based Sign-on* page for the Sonderplan Enterprise app, scroll down to section **2 Attributes & Claims** and click **Edit**

    <img src="https://mintcdn.com/sonderplan-b228cb35/COGNuOeevCLC_Y0F/images/admin/saml-sso/microsoft-entra/microsoft-entra-attributes-claims.png?fit=max&auto=format&n=COGNuOeevCLC_Y0F&q=85&s=655f3ec8ee9b7d140b356b26cb1ee9ea" alt="Microsoft Azure Portal configure saml sso" width="1188" height="663" data-path="images/admin/saml-sso/microsoft-entra/microsoft-entra-attributes-claims.png" />

    2. In the *Attributes & Claims* screen, click the **Unique User Identifier (Name ID)** claim

    <img src="https://mintcdn.com/sonderplan-b228cb35/COGNuOeevCLC_Y0F/images/admin/saml-sso/microsoft-entra/microsoft-entra-manage-claim.png?fit=max&auto=format&n=COGNuOeevCLC_Y0F&q=85&s=b354c07cce5115142081300f967931df" alt="Microsoft Azure Portal configure saml sso" width="1179" height="600" data-path="images/admin/saml-sso/microsoft-entra/microsoft-entra-manage-claim.png" />

    3. Change the **Source Attribute** to ***user.mail*** and click **Save**
  </Accordion>

  <Accordion title="5. Finalise Sonderplan Entra Enterprise Application">
    <img src="https://mintcdn.com/sonderplan-b228cb35/hbMdFMPsN5n2tQkr/images/admin/saml-sso/microsoft-entra/microsoft-entra-saml-step-4.png?fit=max&auto=format&n=hbMdFMPsN5n2tQkr&q=85&s=9ba190d353b779db0827ff25992fa747" alt="Microsoft Azure Portal configure saml sso" width="1070" height="1079" data-path="images/admin/saml-sso/microsoft-entra/microsoft-entra-saml-step-4.png" />

    1. Still in the Sonderplan Enterprise application, expand the **Manage** section, then click on **Properties**
    2. Ensure the **Enabled for users to sign-in?** slider is set to **Yes**
    3. Upload the App Icon to the **Logo** field, which you can save from here:
           <img src="https://mintcdn.com/sonderplan-b228cb35/hbMdFMPsN5n2tQkr/images/icon/Sonderplan-Square-Icon.png?fit=max&auto=format&n=hbMdFMPsN5n2tQkr&q=85&s=55737a8d24cf5fd4b20df168df4847d4" height="150" width="150" alt="Sonderplan App Icon" data-path="images/icon/Sonderplan-Square-Icon.png" />
    4. Change **Assignment required?** slider to **No**
    5. Click **Save** in the top left corner
    6. Finally, you'll need to configure [your users in Sonderplan for SSO](/admin/saml-sso-settings#configure-users-for-sso)
  </Accordion>
</AccordionGroup>

### Okta

Um Sonderplan SAML SSO mit Okta zu konfigurieren, erweitern Sie bitte und befolgen Sie die Anweisungen in jeder Sektion:

<AccordionGroup>
  <Accordion title="1. Create new Okta SAML App">
    <img src="https://mintcdn.com/sonderplan-b228cb35/hbMdFMPsN5n2tQkr/images/admin/saml-sso/okta/okta-create-new-saml-app.png?fit=max&auto=format&n=hbMdFMPsN5n2tQkr&q=85&s=25ced15d97a0ca2a8b97670f8b4e542b" alt="Otka create new SAML app" width="1182" height="790" data-path="images/admin/saml-sso/okta/okta-create-new-saml-app.png" />

    1. In the Okta Admin Console, go to **Applications -> Applications**
    2. Click **Create App Integration**
    3. Select **SAML 2.0** as the Sign-in method, then click **Next**

    <img src="https://mintcdn.com/sonderplan-b228cb35/hbMdFMPsN5n2tQkr/images/admin/saml-sso/okta/okta-saml-general-settings.png?fit=max&auto=format&n=hbMdFMPsN5n2tQkr&q=85&s=f4f6bd1c3144da2b7404ca5b6ec03408" alt="Otka create new SAML app" width="1445" height="752" data-path="images/admin/saml-sso/okta/okta-saml-general-settings.png" />

    4. Enter **Sonderplan** as the **App Name**
    5. Upload the App Icon to the **Logo** field, which you can save from here:
           <img src="https://mintcdn.com/sonderplan-b228cb35/hbMdFMPsN5n2tQkr/images/icon/Sonderplan-Square-Icon.png?fit=max&auto=format&n=hbMdFMPsN5n2tQkr&q=85&s=55737a8d24cf5fd4b20df168df4847d4" height="150" width="150" alt="Sonderplan App Icon" data-path="images/icon/Sonderplan-Square-Icon.png" />
    6. Then click **Next**
  </Accordion>

  <Accordion title="2. Enter Service Provider details into Okta" anchor="ksjdfs">
    1. In Sonderplan, head over to **Admin -> System Settings** and expand the *SAML Single Sign On (SSO)* settings panel
    2. Enable **SAML SSO** and enter **Okta** as the Identity Provider Name
    3. Leave the remaining fields blank for now, and scroll to the section titled *2. Service Provider Details (Sonderplan)*

    <img src="https://mintcdn.com/sonderplan-b228cb35/hbMdFMPsN5n2tQkr/images/admin/saml-sso/okta/sonderplan-sp-copy-settings.png?fit=max&auto=format&n=hbMdFMPsN5n2tQkr&q=85&s=dee3d38060f5c55d45d1ce3a01956d9f" alt="Sonderplan copy service provider settings" width="1328" height="1444" data-path="images/admin/saml-sso/okta/sonderplan-sp-copy-settings.png" />

    4. Copy the **Recipient / ACS (Consumer) URL** from Sonderplan to -> **Single sign-on URL** in Okta Admin
    5. Copy the **Entity ID / Audience / Metadata URL** from Sonderplan to -> **Audience URI (SP Entity ID)** in Okta Admin

    <img src="https://mintcdn.com/sonderplan-b228cb35/hbMdFMPsN5n2tQkr/images/admin/saml-sso/okta/okta-saml-edit-settings.png?fit=max&auto=format&n=hbMdFMPsN5n2tQkr&q=85&s=3a62744f748992bd8383ef3b14f94ac5" alt="Okta Admin SAML setup enter sp settings screenshot" width="1463" height="1606" data-path="images/admin/saml-sso/okta/okta-saml-edit-settings.png" />

    6. Make sure **Name ID format** in Okta Admin is set to **Unspecified**
    7. Set **Application username** in Okta admin to **Email**
    8. In the **Attribute Statements (Optional)** section, define the following mapping:

    | Name           | Name format | Value          |
    | -------------- | ----------- | -------------- |
    | User.email     | Unspecified | user.email     |
    | User.firstName | Unspecified | user.firstName |
    | User.lastName  | Unspecified | user.lastName  |

    9. Click **Next**
    10. Select **I'm an Okta customer adding an internal app**
    11. Check **This is an internal app that we have created**
    12. Click **Finish**
  </Accordion>

  <Accordion title="3. Enter Okta details into Sonderplan">
    <img src="https://mintcdn.com/sonderplan-b228cb35/hbMdFMPsN5n2tQkr/images/admin/saml-sso/okta/okta-copy-idp-settings.png?fit=max&auto=format&n=hbMdFMPsN5n2tQkr&q=85&s=12d36fe5c57f6cb5073736c1a4f02563" alt="Okta Admin SAML copy idp settings screenshot" width="1463" height="1616" data-path="images/admin/saml-sso/okta/okta-copy-idp-settings.png" />

    1. In the Okta Admin panel, click **Sign On** within the *Sonderplan*\* application and scroll down to the **SAML 2.0** section
    2. Copy the **Sign on URL** from Okta to -> **Identity Provider Login URL / SSO Endpoint** in Sonderplan
    3. Copy the **Sign out URL** from Okta to -> **Identity Provider Logout URL / SLO Endpoint** in Sonderplan
    4. Copy the **Issuer** from Okta to -> **Identity Provider Entity ID / Issuer URL** in Sonderplan
    5. Copy the **Signing Certificate** from Okta to -> **Identity Provider X.509 Certificate** in Sonderplan
    6. Click **Save Changes** in the top right corner of Sonderplan
    7. Finally, you'll need to configure [your users in Sonderplan for SSO](/admin/saml-sso-settings#configure-users-for-sso)
  </Accordion>
</AccordionGroup>

## Benutzer für SSO konfigurieren

Nachdem Sie SAML korrekt konfiguriert haben, müssen Sie die SAML SSO-Anmeldung für jeden Ihrer Benutzer in **Admin -> Benutzer & Gruppen -> Benutzer-Editor -> SAML SSO-Login** aktivieren.

<Note>Um versehentliche Kontosperrungen aufgrund möglicher Fehlkonfigurationen oder Ausfälle des Identitätsanbieters zu vermeiden, empfehlen wir, mindestens ein Superadministrator-Konto mit der Standardanmeldeoption zu konfigurieren.</Note>
