Add Talend Administration Center in Okta
This article explains the process to configure Talend Administration Center in Single Sign-on (SSO) mode.
SSO is an authentication process that allows you to access multiple applications with one set of login credentials.
About this task
- Log in to your Okta organization.
- Click the Admin button.
- Click Add Applications, then click the Create New App button.
- Select SAML 2.0, then click Create.
- In the General Settings step, enter a name and description for your application, for example Talend Administration Center, then click Next.
Fill in the SAML Settings
Single sign on URL
Audience URI(SP Entity ID)
Name ID format
Select Email Address in the list.
Select Email in the list.
Update application username on
Select Create and Update in the list.
- Click on Show Advance Settings and configure it as per your organization security requirements.
Click Next and
Finish to open a Sign On page where you can download Identity Provider metadata.
Right-click on the page and save this metadata
file as metadata.xml.
This file is needed later while configuring Talend Administration Center.
Define the user attributes of your application
SSO is only available for Talend Administration Center, but user information of the related applications can be centralized in Okta.
Talend allows you to manage your application user roles and user project types, including roles of Talend Administration Center, Talend Data Preparation and Talend Data Stewardship users, outside of Talend Administration Center from Okta.
Note that once Single-Sign On is enabled, you will not be able to manage from Talend Administration Center all the user settings handled by the Identity Provider, such as user passwords, project types on which users are assigned or user roles.
If you use the LDAP system to handle the SVN and Git credentials, these credentials must be edited through LDAP as Talend Administration Center will automatically retrieve the changes performed.
- From the Okta top menu, select .
- Open the user Profile corresponding to the Talend Administration Center application you have just created in Okta.
- In the Custom tab, click Add Attribute.
- Create the role attribute: In the Add Attribute window, enter the Display Name Attribute (TACRole for example), variable name (tacRole for example), and select string array in the Data type list, then click Add Attribute.
- Create the project type attribute: In the Add Attribute window, enter the Display Name Attribute (TACProjectType for example), variable name (tacProject for example), select string in the Data type list, define a field length (between 1 and 10 characters for example) then click Add Attribute.
Add the user attributes to your application
- Select your existing application and click Edit in the SAML Settings of the General tab.
In the Attribute Statements
area, add the four attributes tac.role,
tac.projectType, firstName and lastName:
Talend Administration Center attribute name
SAML attribute name (Okta)
Attribute value in user profile
Talend Administration Center Role attribute
Any string of your choice that will map the value entered in Talend Administration Center SSO Configuration
tac_admin (for a Talend Administration Center Administrator user)
tac_om (for a Talend Administration Center Operation Manager user)
dp_dm (for a Talend Administration Center Dataset Manager user)
Talend Administration Center Project attribute
Either, DI (Data Integration), DQ (Data Management), MDM (Master Data Management) or NPA (No Project Access)
Optional (if not set, the email address login will be used) - First Name
User first name
Optional (if not set, the email address login will be used) - Last Name
User last name
Define the user information and assign the user to the application
- From the Okta top menu, select .
Select the user you want to edit then go to the
You can decide to add a new user and assign him/her the desired roles.
Set the desired roles values and click Add Another to add several user roles.
Note: You must use the same role and project type values in Talend Administration Center SSO configuration.Do the same for the project type value ((Either, DI (Data Integration), DQ (Data Management), MDM (Master Data Management) or NPA (No Project Access)).
- Open the People view in a new browser tab and click Assign to People.
Enter the username(s) and email address(es) of the person(/people) you want to
assign to the application.
The assigned applications will be shown on the user applications page.Once your application and users are set in Okta, you need to link the Identity Provider to Talend Administration Center in order to retrieve the user information you have defined.
Configure Talend Administration Center
- Log in to Talend Administration Center and open the Configuration page.
- Expand SSO and set Use SSO login to true.
- Click .
- Select the metadata.xml file you saved earlier and click on Upload.
Enter the other parameters as below:
Service Provider Entity ID
IDP Authentication Plugin
Identity Provider Configuration
- Okta Organization URL: Enter your Okta organization URL.
- Okta embedded URL: To know the embedded URL of your account, navigate to the General tab and scroll down to the App Embed Link section.
Copy the Embed link and paste it in the Okta Embeded URL field, then click Save.
Use Role Mapping
Fill in the TAC project types and Roles Mappings settings.
To test the SSO for the newly created user, log in to this
user Okta account.
Talend Administration Center is listed in the user organization Okta portal and you can access it anytime by clicking the icon.
Manage the remote connection in Studio
- Launch your Studio and click Manage Connections.
Create a new Talend Administration Center remote connection.
Click Check url to make sure your connection is
successful then click OK.
A list of all the projects you have access to is displayed.
- Click a project to log in to Studio.