For AI agents: a documentation index is available at the root level at /llms.txt and /llms-full.txt. Append /llms.txt to any URL for a page-level index, or .md for the markdown version of any page.
Logo
DeveloperAcademyCommunityStatus
  • Service Management
    • Overview
    • Concierge & Ticketing Capabilities Overview
    • Forms
    • Forms - Integration Specific Guides
    • Live Agent Chat / Handoff
    • Triage
    • Approval Mirroring
    • Ticket Interception
    • Generic Ticketing Integration: Ticket Gateway
  • Administration
    • MyMoveworks
    • Organization Information
    • Roles and Permissions
    • MyMoveworks SSO
      • Okta SSO Setup
        • Okta Installation Guide (OIDC)
        • Okta Installation Guide (SAML)
        • Okta SSO Configuration Guide for Non-US Commercial Regions (OIDC)
      • Microsoft Entra Setup
      • OneLogin Setup (OIDC)
      • Google SSO Setup (SAML)
      • OIDC Setup (General)
      • SAML Setup (General)
      • SSO Troubleshooting
  • Moveworks Setup
    • Accessing Moveworks Setup
    • First-Time Login via Magic Link
    • Moveworks Setup Modules
    • Moveworks Setup: Module How To Guides
    • Plugin Management
    • Monitor Alerts
    • Audit Logs
    • DSL Fields Defaults
    • Data Crawling View
    • API Playground
    • Setup Homepage
    • Troubleshooting Hub
    • Security and Privacy Settings
    • Configuration Delete
    • Advanced Config Editor
    • Identity configuration
    • Onboarding Stage
  • Security
    • Security
    • Hyperlink & Button Expiry
    • Attachment Handling
    • Moveworks Subprocessors
  • Provision Management
    • Overview
    • Access Software
    • Access Groups
    • Access Account
  • Access Requirements
    • Overview
    • Update Set Modules
    • Ticketing Systems & ITSMs Access
    • Identity and Access Management Systems Access
    • Multi-Factor Authentication (MFA) Systems Access
    • Knowledge Access Requirements
    • Email Distribution List Systems Access
    • Facilities Management Access
    • Live Agent Chat Access
    • HR Information System Access
    • Expense Management Access
    • Calendar Management Access
  • Core Platform
    • User Identity
    • Moveworks On-Prem Agent
    • Approvals Engine
    • Entity Catalog
    • Configuration Languages
    • Moveworks Data Objects
    • SIEM
  • Employee Experience Insights
    • Overview
    • Breaking Down the Dashboard
    • Understanding Industry Benchmarks
    • Apps & Services
    • Impact Module
    • EXI Common Use Cases
    • Configure EXI
    • Ticket Backpolling
  • Knowledge Studio
    • Overview
    • Knowledge Studio Configuration
    • AI Powered Recommendations
    • Inspecting & Verifying Sources
    • Publishing Articles
    • Creating Knowledge Articles
    • Resolving IT Tickets Guidance
DeveloperAcademyCommunityStatus
On this page
  • Before you begin
  • Okta App Setup Instructions
  • Finish the Moveworks side of the integration
AdministrationMyMoveworks SSOOkta SSO Setup

Okta SSO Configuration Guide for Non-US Commercial Regions (OIDC)

||View as Markdown|
Was this page helpful?
Edit this page
Previous

Microsoft Entra Setup

Next
Built with
This guide is deprecated

Please see our updated Okta Installation Guide (🔗)

Before you begin

  • Ensure you have Admin Access to your Okta instance.
  • You have collected the CUSTOMER_ID under Organization Details > General Information.
    • This is the unique identifier for your organization . This is stored as Org Name

      ❗️ The Org name cannot be changed. Once set, the same value should be used in all cases.

      In exceptional cases where you would like Moveworks to support your organisation with a different subdomain value. Please reach out to Moveworks Support.

Okta App Setup Instructions

  1. Go to the screen in Okta that allows you to create Applications.
  2. Click on Create App Integration.

  1. Select OIDC - OpenID Connect in the next screen.

  1. Specify a name for the application.

  2. Add the logo for Moveworks application

    image
  3. Identify the appropriate Sign-in Redirect URI and Login URI for your environment from the table below, replacing the CUSTOMER_ID with the value for your org which was collected as part of the Prerequisites.

RegionSign-in Redirect URILogin URI
United States (default)https://CUSTOMER_ID.moveworks.com/login/sso/oidchttps://CUSTOMER_ID.moveworks.com
Canadahttps://CUSTOMER_ID.am-ca-central.moveworks.com/login/sso/oidchttps://CUSTOMER_ID.am-ca-central.moveworks.com
EUhttps://CUSTOMER_ID.am-eu-central.moveworks.com/login/sso/oidchttps://CUSTOMER_ID.am-eu-central.moveworks.com
Australia / Asia Pacifichttps://CUSTOMER_ID.am-ap-southeast.moveworks.com/login/sso/oidchttps://CUSTOMER_ID.am-ap-southeast.moveworks.com
Government Secure Cloudhttps://CUSTOMER_ID.moveworksgov.com/login/sso/oidchttps://CUSTOMER_ID.moveworksgov.com
  1. Enter the values as shown below and hit Save.

  1. Go back to General Settings and uncheck Require consent.

  1. In order to allow customer users to login without manually inputting email, set a Initiate login URI from the table below based on the Region you are setup in. Replacing the CUSTOMER_ID with the value for your org which was collected as part of the Prerequisites.
RegionSign-in Redirect URILogin URI
United States (default)https://CUSTOMER_ID.moveworks.com/login/sso/oidchttps://CUSTOMER_ID.moveworks.com
Canadahttps://CUSTOMER_ID.am-ca-central.moveworks.com/login/sso/oidchttps://CUSTOMER_ID.am-ca-central.moveworks.com
EUhttps://CUSTOMER_ID.am-eu-central.moveworks.com/login/sso/oidchttps://CUSTOMER_ID.am-eu-central.moveworks.com
Australia / Asia Pacifichttps://CUSTOMER_ID.am-ap-southeast.moveworks.com/login/sso/oidchttps://CUSTOMER_ID.am-ap-southeast.moveworks.com
Government Secure Cloudhttps://CUSTOMER_ID.moveworksgov.com/login/sso/oidchttps://CUSTOMER_ID.moveworksgov.com

Finish the Moveworks side of the integration

After setup is complete, provide the following information to your Customer Success team.

  1. Go to the General tab.

  1. Share the idp_client_id , idp_secret , and idp_issuer with your Customer Success team. The idp_issuer is not in the Okta settings, but it should be based on your Okta instance name (e.g. If you login at https://example.okta.com , then share that value for your idp_issuer ). 1.