Skip to main content

Set up single sign-on

Use SSO Configuration to set up single sign-on (SSO) for your account with your identity provider (IdP). The page supports SAML and OIDC.

Before you start​

  • You need the Administrator user permission.
  • Have the connection details and signing certificate from your identity provider ready. Your identity provider's documentation or administrator can give you these.
  • The settings apply to the account you're currently working in.

Open SSO Configuration​

  1. Select the apps button in the top bar, then select Admin.
  2. Select SSO Configuration.

You can also open it from Admin IT → SSO Configuration in the navigation.

Enter the connection details​

In the Connection Details section:

  1. Select the SSO Enabled checkbox.
  2. In Issuer, enter your identity provider's issuer.
  3. In Login URL, enter your identity provider's sign-in address.
  4. In Entity ID, enter the entity ID or client ID for this connection.
  5. In ACS URL, enter the assertion consumer service (ACS) address for this connection.
  6. In Logout URL, enter your identity provider's sign-out address.
  7. In IdP Certificate, paste your identity provider's signing certificate, including the begin and end lines.

Map user attributes​

In the Attribute Mapping section, match each ScoutIT AI field to the attribute name your identity provider sends.

  1. In Local Field, enter the ScoutIT AI field name.
  2. In IdP Attribute, enter the matching attribute name from your identity provider.
  3. To add another mapping, select + Add mapping.
  4. To delete a mapping, select Remove on its row.

Save and test​

  1. Select Save Configuration.
  2. Wait for the message SSO configuration saved.
  3. Select Test SSO Login to try signing in through your identity provider.

Test SSO Login doesn't save the form. Always save your changes before you test them.

Troubleshooting​

MessageWhat to do
Could not save SSO configuration. Please try again.Try again. If it keeps failing, contact support.
Saved, but the page could not reload.Your settings were saved. Refresh the page to see them.
Unable to determine the current account.Sign out, sign in again, and reopen the page.