Third-party IdP SSO integration

KaseyaOne integrates with third-party identity providers (IdPs) that support SAML 2.0, enabling you to centrally manage users through providers like Okta or Microsoft Entra ID.

The integration between KaseyaOne and the third-party IdP allows users to log in to KaseyaOne from both the IdP interface and the KaseyaOne login page using their IdP credentials. This reduces the amount of user credentials in use and streamlines the login process. You can also add an extra layer of security by forcing users to log in to KaseyaOne from the IdP only.

To get started, you need to configure the SSO integration between KaseyaOne and your third-party IdP. First you will configure the KaseyaOne SSO application in your third-party IdP (refer to Setting up a third-party IdP SSO integration for KaseyaOne). Next, you will configure SSO for your IdP in KaseyaOne (refer to Configure SSO in KaseyaOne for a third-party IdP integration). After completing these procedures, the integration is enabled and you can implement these optional SSO-related features as needed:

  • Enforce Log In with SSO. This forces users to log in with their SSO application.
  • Enable Automatic User Creation. This allows just-in-time provisioning for the third-party IdP SSO application so that user accounts are automatically created with a specified default role when new users authenticate for the first time.
  • IdP Groups Access Control. This allows you to control user access for third-party IdP SSO users.

How to...

Setting up a third-party IdP SSO integration for KaseyaOne

The prerequisites to set up a third-party IdP integration with KaseyaOne are:

  • A KaseyaOne user account with the Admin role and an administrator account in the third-party IdP.
  • Users must have the same email address in KaseyaOne and the third-party IdP.
  • Users and user groups must be set up in the third-party IdP.

The overall process to set up a third-party IdP integration using SAML 2.0 for KaseyaOne is similar across all IdPs and involves the following tasks:

  1. Create and configure the KaseyaOne SSO application in the third-party IdP.

For this task, you will need the Single Sign-On URL and Company Identifier of your KaseyaOne instance. To obtain these values:

  1. Navigate to the  Single Sign-On page.

  2. In the Single Sign-On with Identity Providers section, click Add Configuration.

  3. From the Configure SSO pane that opens, copy and save the values in the Single Sign-On URL and Company Identifier fields.

Once you've obtained your KaseyaOne Single Sign-On URL and Company Identifier, you can configure KaseyaOne SSO in your third-party IdP. (See Third-party IdP SSO integrations using SAML 2.0 with KaseyaOne below for links to detailed instructions for commonly used third-party IdPs.)

  1. Configure the SSO settings in KaseyaOne for the third-party IdP integration. For this task, you will need the third-party IdP's Single Sign-On URL and SSO certificate. Once you've obtained the third-party IdP's Single Sign-On URL and SSO certificate, use this procedure to configure SSO settings in KaseyaOne: Configure SSO in KaseyaOne for a third-party IdP integration.
  2. Assign users to the KaseyaOne application in your third-party IdP so that they will be able to use it.
  3. Test the third-party IdP SSO integration for KaseyaOne.

After you set up the third-party IdP integration, the next time you log in to KaseyaOne you will be prompted to select your preferred method to log in — sign in with Single Sign-On or with your KaseyaOne credentials, unless Enforce Log In with SSO is enabled. We recommend referring to your IdP's documentation when configuring this feature as they will provide the most up-to-date documentation for their platform.

Third-party IdP SSO integrations using SAML 2.0 with KaseyaOne

Set up third-party IdP SSO integrations with KaseyaOne: