SAML SSO

Professional Services can enable a SAML Single Sign-On (SSO) integration to allow users to sign in to an Expert site from your organization's centralized sign-in portal.

Common SAML SSO Terminology

Why is SAML SSO Recommended for Authentication?

Prerequisites

SAML SSO sessions can occur behind existing VPN or IP-restrictions if enabled for your Expert site. See our SAML SSO FAQ for more information on additional security measures.

Collect Information From Your IdP

To configure the most basic SAML SSO integration, you need the following information from your identity provider (IdP):

Enable Group Synchronization (Optional)

  1. Create groups before enabling group synchronization
  2. Familiarize yourself with the behavior of group synchronization
  3. Provide the following additional details:
    1. Group attribute name as it will appear in SAML assertions sent from the IdP to the SP
    2. Group name delimiter character to split the value of the group name attribute into individual group names. If a delimiter character is not provided, the attribute will be treated as an attribute with multiple XML text nodes

Enable Service Provider Message Signing or Encryption (Optional)

Installing an optional private RSA key and x.509 certificate on the SP will allow the SP to sign authentication requests sent to the IdP, and decrypt assertions received from the IdP. If a private RSA key and x.509 certificate are not provided, the public IdP x.509 certificate will still be used to verify incoming SAML assertions from the IdP.

Contact your CXone Mpower Expert Account Manager

Your account manager will introduce you to the team providing SAML SSO integration services. Based on the complexity of your integration, you may need to only supply the IdP data described above, or you may work with them on more advanced integrations. The latter may require more involvement with your IdP maintainer or vendor, and additional information.