Single Sign-On (SSO) lets your users sign in to SV3 Enterprise with their organization account, without a separate SV3 Enterprise password.
How it works
Your organization already knows who your users are through Active Directory or your intranet. With SSO, SV3 Enterprise trusts that sign-in instead of asking for its own credentials.
SV3 Enterprise uses Security Assertion Markup Language (SAML). Your identity provider confirms who the user is and passes that identity to SV3 Enterprise through an exchange of digitally signed XML documents. The identity provider sends each user's email address, and SV3 Enterprise uses it to match the user to their account.
The setup articles use Active Directory Federation Services (ADFS) as the identity provider. ADFS isn't required. If you use a different identity provider, some steps differ. SV3 Enterprise supports any SAML 2.0 based identity provider with OKTA being the most common.
What you need
- A configured Active Directory instance.
- The Email Address attribute filled in for every user in Active Directory.
- ADFS installed on your Active Directory server. See Microsoft's ADFS installation guide.
- An SSL certificate to sign your ADFS sign-in page, and the fingerprint for that certificate.
- A Global Admin in SV3 Enterprise, and an administrator for your ADFS server.
How setup fits together
Setup happens in two places. In SV3 Enterprise, a Global Admin turns on SSO, pastes in your ADFS metadata, and downloads the SV3 Enterprise metadata. In ADFS, an administrator adds SV3 Enterprise as a relying party trust from that metadata. They then add a transform claim rule that sends each user's email address to SV3 Enterprise.
When setup is complete, users see a Login with SSO link on the SV3 Enterprise sign-in page. It takes them to your organization's sign-in page and then back to the Dashboard.
Comments
0 comments
Please sign in to leave a comment.