Managing RealVNC Connect users and roles with Okta

Follow

SSO - Legacy.png
Available-on-all-AddOn-BF.png

If you or your organization have enabled RealVNC Connect's Account SSO and linked your RealVNC Connect Team to Okta, you will no longer be able to invite people within the RealVNC Connect Portal. Instead, people are added to the RealVNC app in Okta and then managed in the RealVNC Connect Portal. To discuss enabling SSO for your subscription, please contact us.

Managers and Admins can use the RealVNC Connect Portal to view, add and remove members of the team as well as assign roles.

Before a user can be added to your RealVNC Connect Team, they must have been assigned to the RealVNC Connect app in Okta.

Okta App Integration Information

Supported Features

Service Provider (SP)-Initiated Authentication (SSO) Flow - This authentication flow occurs when the user attempts to log in to the application from RealVNC Viewer or the RealVNC Connect Portal.

Requirements

In order to proceed with configuring login with SSO through Okta, you must:

  • Have access to an Okta tenant
  • Be an Okta administrator to that tenant
  • Have a RealVNC Connect subscription that includes Account SSO (see the top of this page)

We do not currently offer self-service linking of Okta to your RealVNC Connect Team. To link your RealVNC Connect Team to Okta, please contact our Support team by submitting a ticket here.

Creating an App Integration for RealVNC Connect

This step is only required if you have not already created an app for RealVNC Connect in your Okta admin console.

  1. Navigate to your Okta admin console, and sign in with an account that has appropriate permissions to add applications from the Okta App Catalog
  2. Expand the Applications section on the left menu, then click the Applications menu item

    OktaAdmin1.png

  3. Click the Create App Integration button

    Okta_App_1.png

  4. Choose the OIDC - OpenID Connect option, then choose Native Application and click Next

    Okta_App_2.png

  5. Complete the app integration settings as below:
    1. Enter the name of the integration to be shown to users, for example: RealVNC Connect
    2. Optionally, upload a logo to use for the integration. You can use the logo file, below.

      realvnc-connect.png

    3. Under Core grants, enable the Refresh Token option
    4. Under Advanced, Other grants, enabled Implicit (hybrid)

      Okta_App_3.png

    5. Add the 3 URIs below to Sign-in redirect URIs:
      https://manage.realvnc.com/sso_okta/callback
      https://manage.realvnc.com/sso_client_callback?sso_uri=com.realvnc.vncviewer.sso://localhost/login
      com.realvnc.vncviewer.sso://localhost/login
      
      Okta_App_4.png

    6. Add the URI below to Sign-out redirect URIs:
      https://www.realvnc.com/?signed_out=true
      Okta_App_5.png

    7. Under Assignments, choose Skip group assignment for now
      Assignments will be configured as shown below in the Managing user assignments section

      Okta_App_6.png

  6. Click Save
  7. On the application summary screen, make a note of the Client ID.

    Okta_App_7.png

  8. Update your ticket with the RealVNC Support team with your Client ID and Okta tenant URL, e.g. companyname.okta.com
  9. The RealVNC Support team will create the link with your RealVNC Connect Team and send you a confirmation message once complete.

Managing user assignments

Adding users to the RealVNC App in Okta

  1. Navigate to your Okta admin console, and sign in with an account that has appropriate permissions to assign users to applications
  2. Expand the Applications section on the left menu, then click the Applications menu item

    OktaAdmin1.png

  3. Click the Assign Users to App button

    OktaUser1.png

  4. Select the RealVNC app on the left side of the screen. On the right side, select the Users and/or Groups that you would like to be granted access to RealVNC Connect.

    Click the Next button when you are done.

    OktaUser2.png

  5. Review the assignments and resolve any issues, if applicable, then click the Confirm Assignments button

    OktaUser3.png

  6. Okta will assign the RealVNC app to the selected users/groups and take you back to the Applications page when complete

The user/groups that have been assigned to the RealVNC app will now be able to sign in to RealVNC Connect using their Okta account but will not have access to your RealVNC Connect Team until they have been added using the RealVNC Connect Portal.

Adding Okta users to your Team in the RealVNC Connect Portal

If you are setting up Okta for your RealVNC Connect Team for the first time, or have multiple Okta users to add, please contact our Support team by submitting a ticket here.

  1. Sign in to the RealVNC Connect Portal with an account that holds the Manager, Admin or Owner role
  2. Click People on the left menu

    Portal1.png

  3. Click the Add from organization button

    Portal2.png

  4. On the popup that appears, choose one of the two options.

    Portal3.png

    Choose Add by email if the user you want to add to the team has signed in to RealVNC Connect with Okta previously. Continue to step 5.
    Choose Add by ID if the user you want to add has not signed in to RealVNC Connect with Okta previously. Skip to step 6.

  5. If you want to add by email, click Add a team member and begin typing the email address of the user you want to add. Click on the matching result from the autocomplete. Repeat this for each user you want to add and click the Add button when you are done.

    Portal4.png

  6. If you want to add by id, you will need the email address and user ID of the user you want to add.

    Portal5.png

    To find the Okta user id, you need to sign in to your Okta admin console and either:
    1. In Directory:
      1. Find the user you want to add and click on their name
      2. Copy the User Id from the end of the URL in your web browser's address bar
        OktaUserId.png
    2. In Reports:
      1. Run the User Accounts report under Entitlements and Access
        OktaUserId2.png

Managing roles in your Team

  1. Sign in to the RealVNC Connect Portal with an account that holds the Manager, Admin or Owner role
  2. Click People on the left menu

    Portal1.png

  3. Change the Role dropdown next to the user that you want to change the role for

    Portal6.png

Removing users from your Team

  1. Sign in to the RealVNC Connect Portal with an account that holds the Manager, Admin or Owner role
  2. Click People on the left menu

    Portal1.png

  3. Click the 3 dots button to the right of the user you want to remove, then click Remove

    Portal7.png
Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Article is closed for comments.