The Applications Page Skip to main content
How satisfied are you with the Okta Help Center?
Thank you for your feedback!
How satisfied are you with the Okta Help Center?
Very Dissatisfied
Very satisfied
Enter content less than 200 characters.
The Applications Page
Published: Sep 14, 2017   -   Updated: Jun 22, 2018




The Applications Page

The Applications menu contains options that allow you to assign applications to users individually or in bulk. For an overview of these functions, see Applications.

To open the Applications page

  1. From the Admin Dashboard, click to the Applications drop-down menu.
  2. Choose Applications.
  • Top buttons allow you to easily add (Add Application button) and assign (Assign Applications button) applications for your end users.
  • Clicking the Active or Inactive tabs under the Status column displays your org's active and inactive apps, respectively.
  • The More button reveals the Refresh Application Data function, which works with provisioning to sync roles, profiles, and groups data from configured apps into Okta.
Add applications

The Okta Integration Network (OIN) comes pre-integrated with thousands of applications. These apps appear on each end user's My Applications or Home page for Single Sign On (SSO). As an admin, you can add and assign these applications to your end users. Use the Add Application button to add applications to your system, assign them to users, and configure your sign-on and group settings.

If the application that you want to add does not already exist in the Okta Applications Network, create it with the App Integration Wizard (AIW)

The verification status and supported properties is displayed for each app, as detailed below:

  • Okta Verified indicates that the app was created either from the OIN or by Okta community users, then tested and verified by Okta.
  • Community Created means the app was created by the Okta community, but has not yet been tested and verified by Okta.
  • SAML indicates that the app supports SAML.
  • Provisioning indicates that the app supports one or more of the following provisioning features: push profile updates, push user deactivation, reactivate users, and/or push pending users.

You can also filter for SAML and provisioning properties.

To add an application:

  1. From the Admin Dashboard, click to the Applications drop-down menu.
  2. Choose Applications.
  3. Click Add Application.
  4. Use the alphabetical navigation bar and the search and filtering tools to look for the pre-integrated app that you want to add to your org.

    AIW — If the app you want is not in the OIN, click Create New App to launch the App Integration Wizard (AIW). The AIW allows you to create a custom app (which is a different workflow than the workflow described in this procedure).

    Clone an app — You can clone apps that already have been created in your org. Cloning copies all the settings of the original app to an app with a different name. After cloning, you can modify settings, as needed. To clone an app, click Apps you created under the Create New App button, and then click Clone.

  1. Click Add next to the app that you want to add.
  2. Enter the required information under General Settings, and then click Next.
  3. Configure the settings on the Sign-On Options page:
    • Choose your sign on method – The available options are usually SWA, SAML, or both (depending on what the app supports). Other possibilities include WS-FED, Bookmark only and certain custom sign on modes such as Amazon AWS IAM Role.
      • Secure Web Authentication – When you select the SWA option, Okta signs into the application for each user. This method does not prevent users from signing into the application directly. For more information about configuring SWA apps, see Overview of Managing Apps and SSO.

        Note: If you select SWA and then select the User sets username and password option in the credentials setting, your users initially choose their own usernames and passwords. Note the following about this option:

        • You must select the User sets username and password option if you want to allow end users to take advantage of the Generate a Strong Random Password feature.
        • If users are unassigned from the app and then later reassigned to it, they must reenter their username and password. Users can be unassigned from an app in the following ways:
          • The user is deactivated in Okta.
          • The user is removed from a group that is assigned to the app.
          • The user no longer appears in imports after being deactivated in the app.
          • The organizational unit (OU) that contains the user has been deselected.
      • SAML 2.0 – When you select this option, Okta applies a federated approach to user authentication. All apps that can be configured using SAML have inline instructions that guide you through the configuration.

        Note: To prevent errors in your SAML integrations, ensure that Okta is whitelisted for 3rd-party cookies in your browser! For details, see here.

      • Bookmark only – If you select this option (not supported by all apps), Okta opens a bookmarked web page when users click the app. Your users must manually sign into the application from the bookmarked page.
      • No Sign On – Select this option when adding or configuring mobile apps that don't require any sign on information. Note that if you select this option, only relevant App Settings options are shown under the General tab.
    • Who sets credentials – Specifies who sets the password and username credentials.
    • Default Username – Choose the format to use as the default username value when assigning the application to end users.
  4. Click Done.

To configure additional settings for the new app, cycle through its tabs.


Access and configure general settings, including:

  • App Settings – Configure application-specific settings such as the application label and visibility.


  • Applying this option only affects newly assigned users. This app will not launch automatically for users who are already assigned to it.
  • On apps where auto-launch is enabled here (under the General tab) or by end-users, signing in may cause more than one instance (an additional tab or window) of the app to appear. This is expected behavior. You may safely close any unwanted tabs or windows.
  • VPN Notification – This feature alerts end users when a VPN connection is required to connect to VPN-required apps. When end-users click on an enabled app, a notification displays before the app is launched. You can customize the notification to remind users about VPN requirements. For more information, see VPN Notification.
  • Note: The VPN notification does not appear if the end user has selected the Auto-launch option in the app chiclet General settings. Screenshot


  • App Embed Link – Use this section to retrieve an embed link for the application, redirect users to a custom error page, and redirect users to a custom login page.

Sign On

After you go through the wizard, you can return to the Sign On tab to configure or change sign-on settings. Available options vary by application. You can configure your sign-on methods, credentials details (Application username format; Password reveal), and configure sign-on policies on this tab.


If enabled, allows you to automate user account creation, deactivation, and updates for the app. For more about provisioning, see Provisioning and Deprovisioning Overview.


Assign the app to users you import from an available list of users, or from a CSV file. For details, see Importing people.


Use the Assign button to assign people and groups to the new app. Use the left-side Filters panel to view them.

Note: Because assigning users to apps individually is not very scalable, we recommend that you assign apps to users based on group. For more information, see Assigning Applications (below), or Importing and Using Groups in Okta​.

Push Groups

Group push allows you to use your existing groups in Okta and push them to the app. Once a group is pushed, Okta automatically sends user membership changes to the corresponding group in the app. Requires API Authentication and Provisioning to be enabled for the app. For more information, see Using Group Push.


Only available for OIN applications for which native apps have been tested to work with OMM policies. For more information, see Enabling Mobile Access to Applications.

Assign applications

When setting up or maintaining users, you can assign the applications you want to display on your end users' My Applications or home page. You can assign apps individually, or in bulk.

Assign individual applications:

There are two ways to assign individual apps.

Applications page

  1. From the Applications page, search or scroll down to the application you want to assign to one or more people/groups.
  2. Click the Action button drop-down menu. ActionButton
  3. Choose Assign to Users or Assign to Groups.

Specific app

  1. From the Applications page, search or scroll down to the app you want to assign to one or more people/groups.
  2. Click the individual app to view its page.
  3. On the app specific page, click the Assign button.
  4. Choose either Assign to People or Assign to Groups. An Assign <app name> to People /Assign <app name> to Groups dialog appears listing available end users or groups who are not already assigned to the selected app.
  5. Click the Assign button next to each user or group for which you want this app assigned. For users, complete the Attributes page.
  6. Assign more users/groups, or click Done.

Assign applications in bulk:

  1. From the Applications page, click Assign Applications.

    The Assign Applications page appears. On the left of this screen is a list of available Applications. On the right of the screen, there is a list of People in your org.

  2. From the list of available Applications, select the application(s) that you want to assign to users. Selecting the checkbox at the top of the list selects all listed applications.
  3. From the list of People in your org, select the users to whom you want to assign the selected application(s).

    Selecting the checkbox at the top of the list assigns the applications to all users. Alternatively, you can search by group:

    (a) Select Search by group in the drop-down menu next to the People search field.

    (b) Enter the name of the group, then select the users.

  4. Click Next.
  5. Review the summary page and complete any additional information requested on the page.
  6. Click Confirm Assignments.

Manage assignments for an app

An enhanced app assignment screen is available that shows people and groups on the same screen with a toggle. From the Applications page, select an app and then click Assignments.

  • To filter the display between Groups and Users, use the toggle buttons in the Filters column. Only users and groups to whom the app is already assigned are displayed.
  • To assign the app to new users or groups, click the Assign button and select either Assign to People or Assign to Groups. Then, click Assign as desired from the list that appears.
  • This screen displays an error message if an assignment cannot be completed. To edit an assignment, click the pencil icon next to the name. To delete an assignment, click the X icon.

Additionally, custom attributes that are set up for an app contain a default mapping. You can now override the default mapping for an individual and enter a value for the attribute and reset the custom value to the default value automatically.

Example: For an app, you can set up a custom variable Nickname that is mapped by default to the Firstname field. For a user assigned to an app, you can enter a nickname and, if desired, reset the nickname to the default value.

Prerequisites: The custom variable must already be set up.

To set the custom value, assign the individual to the app or edit an assigned user. In the edit panel, all custom variables appear, as shown below, but no value is displayed.

  • To keep the default value, no action is necessary.
  • To add a custom value, enter the value and click Save.
  • To reset a custom value to the default value, click the reset icon below the value. The calculated default value for that user displays. When done, click Save.


Enable Federation Broker Mode

This is an Early Access feature. To enable it, please contact Okta Support.

Federation Broker Mode allows for SSO without the need to pre-assign apps to specific users. Access is managed only by sign-on policy and the authorization rules of each app. This mode can improve import performance and can be especially helpful for larger-scale orgs that manage many users and/or apps.

This mode is a powerful option with some important considerations:

  • This mode is only available for custom SAML Wizard and OIDC apps, not for those available in the OIN.

  • Provisioning cannot be enabled while using this mode.
  • This option is not appropriate for apps that require end-user access through the chiclets of the Okta Homepage.

  • Enablement of this option hides certain tabs that are no longer functional with this feature. Hidden tabs may include Provisioning, Imports, Group Push, and Mobile.
  • This mode makes the app available to all users through SP-initiated flows only—specific assignments are not possible. So, if an app was assigned prior to enabling this mode, any existing assignment data may be lost. Again, enabled apps do not appear on the Okta Homepage.
  • The page under the Assignments tab of an enabled app no longer lists user assignments, as it is no longer subject to individual assignments.


  • Enabled apps do not provide audit reporting.
  • If you choose to disable this mode after implementation, you can restore previously created assignments.

To access Federation Broker Mode, go to the app page of a SAML Wizard or OIDC app.

  1. From the Applications page, search or scroll down to the app you want to enable.
  2. Click the individual app to view its page.
  3. On the app page, click the Sign On tab.
  4. Scroll down to the Federation Broker Mode section.
  5. Click the Enable Federation Broker Mode button. Note the considerations listed for enabling this option.
  6. After reading through the list, click the Enable Federation Broker Mode button to enable it.

Disabling Federation Broker Mode

If you should later choose to disable Federation Broker Mode, do the following:

  1. From the Applications page, search or scroll down to the app you want to disable.
  2. Click the app to view its page.
  3. On the app page, click the Sign On tab.
  4. Scroll down to the Federation Broker Mode section.
  5. Click the Disable Federation Broker Mode button. Note that disablement is not immediate, but the app remains in federation broker mode to ensure that your end-users will not lose access while it completes disablement.

When completed, your previous tabs and assignments are restored.

Convert applications from Individually-Owned to Group-Managed

You can convert application access and user properties settings so that individually owned applications become group managed. Converting assignments has the following effects:

  • User properties are managed by the group. Changes at the group level are applied to all users managed by the group.
  • Application access is managed by the group. Removing an application from the group removes the app from the user.

You can determine whether a user's application assignment is individually or group-managed by selecting the user on the People page. The assignment displays as Individual or shows the group name (shown as The New School below).


To convert application assignments from individual to group, do the following:

  1. From your Dashboard, select Applications.
  2. From the list of apps, find the app you wish to convert.
  3. Click the Convert Assignments button
  4. Select the desired users and then click the Convert Selected button or, to convert all your users, click the Convert All button.
  5. Click Yes to confirm the change.

    A confirmation message appears that provides the total number of converted users.

Show application embed links

To embed an Okta-managed application in a portal or other external location by obtaining the embed link:

  1. Click the Action button drop-down menu ActionButtonadjacent to the desired app. Choose Copy embed link to clipboard.
  2. The embed link URL is automatically copied. Paste it into your portal or other external location outside of Okta.

You can now sign into this app outside of Okta. To stop displaying the embed links, click Hide app embed links.

Note: Alternatively, you can obtain an embed link by selecting an application, selecting its General tab, and copying the URL provided in the Application Embed Link section.

Redirect unauthenticated users to a custom login page

If unauthenticated users attempt to access an Okta-managed application outside of Okta, you can redirect them to a default or custom login page.

  1. From the Applications page click an application.
  2. Click the General tab.
  3. Click Edit in the App Embed Link section.
  4. Select one of the following in the Application Login Page section:
    • Use the default organization login page – This is the default setting. Unauthenticated users are redirected to the Okta login page.
    • Use a custom login page for this application – If you select this option, enter the URL to the custom login page. Okta will append the relay state via a query parameter called fromURI.

      Note: Your Service Provider must be configured to use a GET binding when validating the response. POST bindings are not supported.

      The redirect URL to your custom login page will be url-encoded and look similar to this:
  5. Click Save.
Redirect unassigned users to a custom error page

If end users attempt to access an app to which they are not assigned, you can configure Okta to automatically redirect them to Okta's default URL or a custom URL that you provide. Unassigned users are more likely to try to access apps if you embed app links in your portal or other sites outside of Okta.

  1. From the Applications page click an application.
  2. Click the General tab.
  3. Click Edit in the App Embed Link section.
  4. Select one of the following in the Application Access Error Page section:
    • Use the error setting on the global settings page – Select this option if you want to redirect unassigned users to the same default URL specified in the org-level (global) setting (Settings > Customization > Configure an Application Access error page).
    • Use a custom error page for this application – Select this option if you want to redirect unassigned users of this app to a custom URL that you provide. This app-specific option overrides the default org-level setting described in the previous bullet.
  5. Click Save.
Deactivate an app

Note: This process only deactivates the app. The app remains under the Inactive tab unless it is permanently deleted, as is detailed in Deleting an App below.

  1. From the Dashboard, select Applications.
  2. From under the Status column, click the Active tab to find the app you want to deactivate.
  3. From the Action button drop-down menu, ActionButtonchoose Deactivate.
Delete an app

Caution: Deleting an app is permanent. Once an app is deleted, it is not possible to re-activate the app or its memberships.

  1. From the Dashboard, select Applications.
  1. Click the Inactive tab. (If the app you wish to permanently delete is currently active, you are directed to deactivate it first).
  1. From the Inactive drop-down menu, choose Delete.
Add notes to an app

This is an Early Access feature. To enable it, please contact Okta Support.

You can add notes to apps during app creation or at any time to communicate with end users and other admins about apps. In addition to enhancing app deployment and usage, app notes can also reduce help desk calls, provide troubleshooting assistance, and increase end-user self service.

App notes facilitate the following types of communications:

  • Application notes to end users – Allows admins to present helpful information to end users, such as the purpose of the app, who to contact for help, and links to information. Screenshot
  • AppNotes-EndUsers

  • Application notes to admins – Allows admins to share administrative details about apps with other Super, App, Read-only, and Mobile admins. Screenshot
  • AppNotes-Admins

  1. Go to Applications.
  2. Click the app in which you want to add app notes.
  3. Click the General tab.
  4. Enter notes in the app note fields for end users and/or admins. If an app contains app notes for end users, an icon appears below the app chiclet on end user dashboards and an App Notes tab appears in app settings.
  5. Note the following:

    • Notes cannot exceed 250 characters, including spaces.
    • To enter a link or an email address, simply type it in the field. These are converted to links in the admin-to-end user app note after you save it. Supported link protocols are http, https, and ftp.
    • Admin-to-admin app notes are visible only to Super, App, Read-only, and Mobile admins.
    • HTML tags are not supported.
  6. Click Save.
Customize an application logo

You can customize an application logo by replacing it with your own image. The custom logo must meet the following requirements:

  • Image type must be .png, .jpg, or, .gif (.png is recommended)
  • Image dimensions can't exceed 140 x 40 px
  • Image size must be less than 25k
  1. From the Dashboard, select Applications.
  2. Locate and click the app whose logo you want to customize.
  3. Mouse over the app's current logo, then click the pencil icon.
  4. In the Edit Logo dialog box, click Browse to find the custom logo file, and then click Update Logo.
  5. Click Close. The updated logo is visible to all users who have been assigned this app.

To revert to the original image, follow the same steps to access the Edit Logo dialog box, and then click Reset logo.

Use Self Service

You can enable and manage applications to allow your end users to add apps from their My Applications (or Home) page.

  1. Select Applications > Self Service.
  2. On the Settings tab, click Edit in the Self Service Application Assignment section.
  3. Under Permissions, select the Enable self service application assignment check box, and then choose which apps to show:
    • Show organization and end-user managed apps
    • Show organization managed apps only
    • Show end-user managed apps only
  4. In Organization Managed Apps, select the apps that you want to appear in the organization tab of the self service app catalog, and then click Save.