Dynamic SAML Attributes

As part of Configuring SAML for new or existing OIN applications, you can optionally define custom SAML Attribute Statements.

  • You can federate Okta user attributes to SAML attributes.
  • The Service Provider will use the federated SAML attribute values accordingly.
  • Attribute names must be unique. This is not just limited to group attributes, the uniqueness constraint is across all attributes, so for example you can't have a group attribute and a regular attribute with the same name.

Attribute Statements

1. Enter the Name of an Okta attribute.

2. Optionally select a Name format.

3. Enter a Value.

4. Click Add Another until you have defined all the attributes you need.

Group Attribute Statements

If your orgThe Okta container that represents a real-world organization. supports a large number of groupsGroups allow you to organize your end users and the apps they can access. Assigning apps to large sets of end users is made easier with groups., use this option to filter them into a single SAML assertion:

1. Enter a group Name.

2. Optionally select a Name format.

3. Enter a Filter. Filtering options include Starts With, Equals, Contains, and Regex expressions.

4. Click Add Another until you have defined all the groups you need.

For details on creating custom expressions, see Okta Expression Language.

Preview SAML

Click Preview SAML to display the SAML assertion that will be sent based on your Attribute Statement definitions.