SSO Management
BastionZero supports Google, Microsoft, Okta, OneLogin, and Keycloak identity providers.
Google
Set up your Google organization with BastionZero
Use Google groups to simplify access management
Microsoft
Set up your Microsoft organization with BastionZero
Use Microsoft groups to simplify access management
Okta
Set up your Okta organization with BastionZero





Use Okta groups to simplify access management

Create your Okta app integration 
Client Credentials panel

Image showing the needed configuration for General Settings and Federation Broker Mode 
Enable okta.groups.read and okta.users.read for your BastionZero and Okta integration to work correctly 
Example of Admin role page without any created roles 
Example of the Group Administrator role 
What your Admin roles screen should look like once you have created your Group Administrator role 

Use your Okta Client ID to integrate your Okta organization with BastionZero
OneLogin
Set up your OneLogin organization with BastionZero




Use OneLogin groups to simplify access management


Keycloak
Set up your Keycloak organization with BastionZero





Ensure that email, offline_access, and profile have the Default assigned type.
Use Keycloak groups to simplify access management


Client authentication and Authorization are required for access to api.
query-groups, query-users and view-users roles are assigned.

Last updated
