Organization single sign-on
Offer SAML single sign-on to an eligible organization's members while keeping setup responsibilities clear.
Eligible Enterprise organizations can offer single sign-on (SSO) for members who use the organization's email domain.
What an organization admin configures
Open the organization's SSO panel and provide:
- the claimed email domain, such as
acme.com; - the identity provider's provider ID; and
- whether SSO should be offered for that domain.
The domain belongs to one organization. Save the configuration, then use Verify connection to confirm that the identity provider answers.
Set up the identity provider first
The SAML connection itself is registered in your identity platform. The setup generally requires the provider metadata, ACS URL, entity ID, and signing certificate shown by that platform. Once it is registered, copy the provider ID into BeaconUAV and verify it.
BeaconUAV stores the organization's domain/provider claim and verification status; it does not create the SAML connection or hold the provider's signing secret.
Member sign-in
When SSO is offered, a member who enters an email from the claimed domain is routed to the configured provider. SSO is offered, not forcibly imposed by this panel: password sign-in remains available until the organization's identity-provider policy disables it.
Verify the domain and provider before switching SSO on. If the connection stops answering, an administrator can switch the offer off while the identity platform is repaired.