Your enterprise identity team has provisioned Instana as a SAML 2.0 Service Provider and wants employees to authenticate using corporate credentials from Okta as the Identity Provider. Which configuration step must the Instana administrator complete in the Instana Settings to enable SAML SSO?
Select an answer to reveal the explanation.
Short Explanation and Infographic
SAML SSO in Instana is enabled by supplying the Identity Provider metadata, which includes the SSO endpoint URL and the signing certificate used to verify SAML assertions, under Settings > Authentication > SAML. Administrators can upload the IdP metadata XML file or enter the details manually, after which Instana redirects unauthenticated users to the corporate IdP for login. LDAP is a separate directory protocol and cannot fulfill a SAML 2.0 federation requirement.
Full explanation below image
Full Explanation
SAML SSO in Instana is enabled by supplying the Identity Provider metadata, which includes the SSO endpoint URL and the signing certificate used to verify SAML assertions, under Settings > Authentication > SAML. Administrators can upload the IdP metadata XML file or enter the details manually, after which Instana redirects unauthenticated users to the corporate IdP for login. LDAP is a separate directory protocol and cannot fulfill a SAML 2.0 federation requirement. The correct answer is 'Upload the IdP metadata XML from Okta — or manually enter the IdP SSO URL and signing certificate — under Settings > Authentication > SAML'. The incorrect options — 'Configure an LDAP connection pointing to the Okta directory under Settings > Authentication', "Create API tokens scoped to each user's Okta account and distribute them for script-based login", 'Enable OAuth 2.0 client credentials flow under Settings > Integrations > Identity Providers' — are wrong because they do not align with IBM Instana's architecture or recommended practices for this scenario. Understanding this concept is essential for the Domain 7: Security/Compliance domain of the IBM Instana Observability certification.