Below is a general overview of the transition process. Because each application or system may have different configuration requirements, owners should review the relevant system documentation and Knowledge Base articles before making changes. Additionally, make sure to consult your service or systems documentation for specific configuration options before beginning any maintenance to ensure proper settings are applied. SSO configurations are managed by service owners and their administrators; IAM does not maintain service SSO configurations.
General Procedure for Transitioning to Okta
Before you get started, make sure you have the following prerequisites:
- A plan for the maintenance activities that includes how you will communicate to customers of your system about the change.
- Administrative access to the server or system
- Access and knowledge to update single sign-on configurations
- An MCommunity group with members that are authorized to administer the service or system
- For RDP connections, allow up to a week between creating your application in AMP and performing maintenance on your service or system
- If you are transitioning an SSH or RDP configuration, ensure you have local access to the system to prevent system lockout.
General Process
IAM recommends transitioning a non-production system first to become familiar with the process.
- In the AMP self-service tool, create your application and generate the required integration.
- Access your service or system using an administrator account.
- For RDP or SSH integrations, you must remove any Duo integrations before installing Okta modules.
- Follow the instructions for your service or system to point to the appropriate okta.umich.edu endpoints.
- Save and test your configuration.
How to transition to Okta
The Application Management and Provisioning (AMP) self-service migration tool is available to create the necessary integrations to transition your services and applications to Okta (campus network or VPN required to access AMP).
Service Owners are expected to configure their applications to use the integrations created in AMP as well as communicate to users of their service about maintenance activities. Knowledge Base (KB) articles (linked below) are available for each type of single sign-on (SSO) connection. These articles contain important information about creating an application in AMP and preparing for a service’s transition to Okta. KBs for secure shell (SSH) and remote desktop protocol (RDP) also include downloads and installation steps:
- Creating an RDP Application in the AMP Application
- Creating an SSH Application in the AMP Application
- Creating an OIDC Application in the AMP Application
- Creating an SAML Application in the AMP Application
Get Help
- Join our office hours on:
- Open a ticket with the ITS-IAM team
