Setup SSO
发布时间:2026-08-16 | 浏览:6
This setup might fail without parameter values that are customized for your organization. Please use the Okta Administrator Dashboard to add an application and view the values that are specific for your organization.
The Concur Travel and Expense app is currently in Early Access stage. For more information contact your Concur representative.
Supported Features
Configuration Steps
How to create your own SAML application with encryption option enabled
Concur Mobile SSO Configuration Steps
Supported Features
The Okta/Concur Travel and Expense SAML integration currently supports the following features:
IdP-initiated SSO
SP-initiated SSO
For more information on the listed features, visit the Okta Glossary .
Configuration Steps
Login to SSO management page based on the region your Concur entity is hosted in: US : https://www.concursolutions.com/nui/authadmin/ssoadmin EMEA : https://eu1.concursolutions.com/nui/authadmin/ssoadmin China : https://www.concurcdc.cn/nui/authadmin/ssoadmin Note : If you can’t access the URL, contact Concur Support.
Login to SSO management page based on the region your Concur entity is hosted in:
US : https://www.concursolutions.com/nui/authadmin/ssoadmin
US : https://www.concursolutions.com/nui/authadmin/ssoadmin
EMEA : https://eu1.concursolutions.com/nui/authadmin/ssoadmin
EMEA : https://eu1.concursolutions.com/nui/authadmin/ssoadmin
China : https://www.concurcdc.cn/nui/authadmin/ssoadmin
China : https://www.concurcdc.cn/nui/authadmin/ssoadmin
Note : If you can’t access the URL, contact Concur Support.
Scroll down to the IdP Metadata section and click Add :
Scroll down to the IdP Metadata section and click Add :
Follow the steps below: Custom IdP Name : Enter a name for your IdP. Provide link to your IdP's metadata : Copy and paste the following: Sign in to the Okta Admin app to have this variable generated for you Click Add Metadata :
Follow the steps below:
Custom IdP Name : Enter a name for your IdP. Provide link to your IdP's metadata : Copy and paste the following: Sign in to the Okta Admin app to have this variable generated for you Click Add Metadata :
Custom IdP Name : Enter a name for your IdP.
Provide link to your IdP's metadata : Copy and paste the following: Sign in to the Okta Admin app to have this variable generated for you
Provide link to your IdP's metadata : Copy and paste the following:
Sign in to the Okta Admin app to have this variable generated for you
Click Add Metadata :
Click Add Metadata :
This application does not support the encryption option. In order to activate this, you need to create your own private application through our SAML App Wizard . Instructions are provided below .
SP-initiated SSO
Go to the URL below based on the region your Concur entity is hosted in, then click Try our new sign in experience once it’s available: US : https://www.concursolutions.com EMEA : https://eu1.concursolutions.com China : https://www.concurcdc.cn
Go to the URL below based on the region your Concur entity is hosted in, then click Try our new sign in experience once it’s available:
US : https://www.concursolutions.com
US : https://www.concursolutions.com
EMEA : https://eu1.concursolutions.com
EMEA : https://eu1.concursolutions.com
China : https://www.concurcdc.cn
China : https://www.concurcdc.cn
Enter your Username , then click Next :
Enter your Username , then click Next :
How to create your own SAML application with encryption option enabled
Based on your location, save, then open one of the following SP metadata files in any text editor: US : https://us.api.concursolutions.com/sso/saml2/V1/sp/metadata/ EMEA : https://emea.api.concursolutions.com/sso/saml2/V1/sp/metadata/ Locate and save the values for the following parameters (we used the US SP metadata in our examples): entityID : encryption certificate : Paste the copied certificate into a text file, between two BEGIN/END CERTIFICATE rows as shown below: -----BEGIN CERTIFICATE----- << your copied certificate >> -----END CERTIFICATE----- Save as Encryption.crt . Location : In Okta, select Applications > Add Application > Create New App : Select SAML 2.0 as the Sign on method , then click Create : Enter your preferred App name , optionally add a logo, then click Next : Follow the steps below: Single sign on URL : Enter your Location value you saved in step 2. Select Use this for Recipient URL and Destination URL . Audience URI (SP Entity ID) : Enter the entityID value you saved in step 2. Name ID format : select EmailAddress . Click Show Advanced Settings : Assertion Encryption : Select Encrypted . Encryption Certificate : Click Browse to locate and upload the encryption.crt you saved in step 2. Click Next : Follow the steps below: Are you a customer or partner? : Select I'm an Okta customer adding an internal app . App type : Select This is an internal app that we have created . Click Finish : Done!
Based on your location, save, then open one of the following SP metadata files in any text editor:
US : https://us.api.concursolutions.com/sso/saml2/V1/sp/metadata/
US : https://us.api.concursolutions.com/sso/saml2/V1/sp/metadata/
EMEA : https://emea.api.concursolutions.com/sso/saml2/V1/sp/metadata/
EMEA : https://emea.api.concursolutions.com/sso/saml2/V1/sp/metadata/
Locate and save the values for the following parameters (we used the US SP metadata in our examples): entityID : encryption certificate : Paste the copied certificate into a text file, between two BEGIN/END CERTIFICATE rows as shown below: -----BEGIN CERTIFICATE----- << your copied certificate >> -----END CERTIFICATE----- Save as Encryption.crt . Location :
Locate and save the values for the following parameters (we used the US SP metadata in our examples): entityID : encryption certificate : Paste the copied certificate into a text file, between two BEGIN/END CERTIFICATE rows as shown below: -----BEGIN CERTIFICATE----- << your copied certificate >> -----END CERTIFICATE----- Save as Encryption.crt . Location :
encryption certificate : Paste the copied certificate into a text file, between two BEGIN/END CERTIFICATE rows as shown below: -----BEGIN CERTIFICATE----- << your copied certificate >> -----END CERTIFICATE----- Save as Encryption.crt .
encryption certificate :
Paste the copied certificate into a text file, between two BEGIN/END CERTIFICATE rows as shown below: -----BEGIN CERTIFICATE----- << your copied certificate >> -----END CERTIFICATE-----
Paste the copied certificate into a text file, between two BEGIN/END CERTIFICATE rows as shown below:
Save as Encryption.crt .
Save as Encryption.crt .
In Okta, select Applications > Add Application > Create New App :
In Okta, select Applications > Add Application > Create New App :
Select SAML 2.0 as the Sign on method , then click Create :
Select SAML 2.0 as the Sign on method , then click Create :
Enter your preferred App name , optionally add a logo, then click Next :
Enter your preferred App name , optionally add a logo, then click Next :
Follow the steps below: Single sign on URL : Enter your Location value you saved in step 2. Select Use this for Recipient URL and Destination URL . Audience URI (SP Entity ID) : Enter the entityID value you saved in step 2. Name ID format : select EmailAddress . Click Show Advanced Settings : Assertion Encryption : Select Encrypted . Encryption Certificate : Click Browse to locate and upload the encryption.crt you saved in step 2. Click Next :
Follow the steps below:
Single sign on URL : Enter your Location value you saved in step 2. Select Use this for Recipient URL and Destination URL . Audience URI (SP Entity ID) : Enter the entityID value you saved in step 2. Name ID format : select EmailAddress . Click Show Advanced Settings : Assertion Encryption : Select Encrypted . Encryption Certificate : Click Browse to locate and upload the encryption.crt you saved in step 2. Click Next :
Single sign on URL : Enter your Location value you saved in step 2. Select Use this for Recipient URL and Destination URL . Audience URI (SP Entity ID) : Enter the entityID value you saved in step 2. Name ID format : select EmailAddress . Click Show Advanced Settings : Assertion Encryption : Select Encrypted . Encryption Certificate : Click Browse to locate and upload the encryption.crt you saved in step 2. Click Next :
Select Use this for Recipient URL and Destination URL .
Select Use this for Recipient URL and Destination URL .
Audience URI (SP Entity ID) : Enter the entityID value you saved in step 2.
Audience URI (SP Entity ID) : Enter the entityID value you saved in step 2.
Name ID format : select EmailAddress .
Name ID format : select EmailAddress .
Click Show Advanced Settings :
Click Show Advanced Settings :
Assertion Encryption : Select Encrypted .
Assertion Encryption : Select Encrypted .
Encryption Certificate : Click Browse to locate and upload the encryption.crt you saved in step 2.
Encryption Certificate : Click Browse to locate and upload the encryption.crt you saved in step 2.
Follow the steps below: Are you a customer or partner? : Select I'm an Okta customer adding an internal app . App type : Select This is an internal app that we have created . Click Finish :
Follow the steps below: Are you a customer or partner? : Select I'm an Okta customer adding an internal app . App type : Select This is an internal app that we have created . Click Finish :
Are you a customer or partner? : Select I'm an Okta customer adding an internal app .
Are you a customer or partner? : Select I'm an Okta customer adding an internal app .
App type : Select This is an internal app that we have created .
App type : Select This is an internal app that we have created .
Concur Mobile SSO Configuration Steps
Using the processes described above does not automatically activate mobile SSO. To enable SSO for the SAP Concur mobile app, follow the steps below:
Find the HTTP-Redirect URL from your IdP metadata: Locate the IdP metadata you previously uploaded to SAP Concur. Look for HTTP-Redirect URL in the IdP metadata. For example: <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location=" https://acme.okta.com/app/concur_travel_expense/123456/sso/saml"/> Contains the URL https://acme.okta.com/app/concur_travel_expense/123456/sso/saml . Test the HTTP-Redirect URL in a web browser and verify that you can sign in to SAP Concur with this URL. Provide the HTTP-Redirect URL to SAP Concur support. They will ensure that this URL is added properly as the Mobile SSO URL on Concur side.
Find the HTTP-Redirect URL from your IdP metadata:
Locate the IdP metadata you previously uploaded to SAP Concur. Look for HTTP-Redirect URL in the IdP metadata. For example: <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location=" https://acme.okta.com/app/concur_travel_expense/123456/sso/saml"/> Contains the URL https://acme.okta.com/app/concur_travel_expense/123456/sso/saml .
Locate the IdP metadata you previously uploaded to SAP Concur. Look for HTTP-Redirect URL in the IdP metadata.
<SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location=" https://acme.okta.com/app/concur_travel_expense/123456/sso/saml"/>
Contains the URL https://acme.okta.com/app/concur_travel_expense/123456/sso/saml .
Test the HTTP-Redirect URL in a web browser and verify that you can sign in to SAP Concur with this URL.
Test the HTTP-Redirect URL in a web browser and verify that you can sign in to SAP Concur with this URL.
Provide the HTTP-Redirect URL to SAP Concur support. They will ensure that this URL is added properly as the Mobile SSO URL on Concur side.
Provide the HTTP-Redirect URL to SAP Concur support. They will ensure that this URL is added properly as the Mobile SSO URL on Concur side.
Work with Concur Support and learn how to use SSO to login Concur mobile.
Work with Concur Support and learn how to use SSO to login Concur mobile.