Using the Okta configuration for Ideagen Hub
Who is this article for?
IT Administrators who want to learn to use the Okta configuration.
IT administrator permissions are required.
This article explains how to identify which Okta configuration you are currently using with Ideagen Please Review, and what actions are required to ensure a successful migration to Ideagen Hub.
1. Understanding why this matters
Ideagen Hub and Ideagen Please Review cannot always share the same Okta SAML configuration. The steps you need to follow depend on how your existing Okta integration is set up today. Identifying your configuration early helps avoid login disruption during migration.
2. Checking which Okta configuration you are using
To identify your current Okta configuration, follow these steps:
- Open Applications.
- Select Applications.
- Select your Ideagen Please Review application.
- Check for either of the following:
- A Ideagen Please Review logo on the application
- A field called Ideagen Please Review URL shown under the General tab
If you see either of these, you are using the Ideagen Please Review OIN application.
3. Understanding configuration types and required actions
Your next steps depend on whether you are using the Ideagen Please Review OIN application.
3.1. You are using the Ideagen Please Review OIN application
The OIN application cannot be reused for Ideagen Hub. A new Okta application is required.
To prepare for migration, follow these steps:
- Create a new Okta SAML application for Ideagen Hub.
- Wait for Ideagen to migrate your tenant, products, and users to Hub (all users are initially migrated as Internal Users).
- Configure the new Okta application in the Ideagen Hub Admin Console.
- Export users.
- Update Authentication Type to External.
- Re-import the users.
No changes are required to your existing Ideagen Please Review SSO before migration. Users continue logging into Ideagen Please Review during setup. Once configuration is complete, users can log into Hub using the new Okta app.
3.2. You are not using the Ideagen Please Review OIN application
Ideagen Please Review and Ideagen Hub use separate Okta applications.
To prepare for migration, follow these steps:
- Create a new Okta SAML application for Ideagen Hub.
- Wait for Ideagen to migrate your tenant, products, and users to Hub (all users are initially migrated as Internal Users).
- Configure the new Okta application in the Ideagen Hub Admin Console.
- Export users.
- Update Authentication Type to External.
- Re-import the users.
4. Settings overview
Here are known settings for Oka integration to Hub to work with PR:
Using these profile attributes statements:
- preferred_username > Basic > user.email
- email > Basic > user.email

SAML Settings
- Single Sign On URL: https://_________.auth._______.amazoncognito.com/saml2/idpresponse
- Recpient URL: https://_________.auth._______.amazoncognito.com/saml2/idpresponse
- Desitnation URL: https://_________.auth._______.amazoncognito.com/saml2/idpresponse
- Audience Restriction: urn:amazon:cognito:sp:________ (eg us-east-1_Avcd8efG in _____)
- Default Relay State: Copied form the Hub portal SAML2 settings
- Name ID Format: Email Addres
- Response: Signed
- Assertion Signature: Signed
- Signature Algorithm: RSH_SHA256
- Digest Algorithm: SHA256
- Assertion Encryption: Unecrypted
5. Getting help
If you are unsure which configuration you are using, or which option is best for your environment, contact Ideagen Support or your customer success representative before your scheduled migration date. Early confirmation helps ensure a smooth, disruption-free transition to Ideagen Hub.