Third-party IdP SSO integration

SECURITY  Master role

KaseyaOne supports third-party identity provider (IdP) single sign-on (SSO) integrations. Using a third-party IdP that supports SAML 2.0 (such as Okta or Microsoft Entra ID), you can centrally manage your users allowing them to access KaseyaOne via SSO. You can also connect your own custom server if it supports SAML 2.0.

The integration between KaseyaOne and third-party IdP allows users to log in to KaseyaOne from both the IdP interface and the KaseyaOne login page using the IdP credentials. This reduces the amount of user credentials in use and streamlines the login process. The integration allows automatic user provisioning to the KaseyaOne account from the IdP and in doing so reduces the amount of time spent on user administration. You can also add an extra layer of security by forcing users to log in to KaseyaOne from the IdP only.

You manage your third-party identity provider SSO integration and the following SSO-related features in the Admin Settings > Third-party IdP view:

  • Require Log In with Single Sign-On. This forces users to log in with their SSO application.
  • Automatic User Creation. This allows just-in-time provisioning for the third-party IdP SSO application so that user accounts are automatically created with a specified default role when new users authenticate for the first time.
  • Role-based access control. This allows you to control user access for third-party IdP SSO users.

How to...

Set up a third-party IdP SSO integration for KaseyaOne

The overall process to set up a third-party IdP integration using SAML 2.0 for KaseyaOne is similar across all IdPs and involves the following tasks:

  1. Create and configure the KaseyaOne SSO application in the third-party IdP. For this task, you will need to copy the Single Sign-On URL and Company Identifier for your KaseyaOne instance from the Admin Settings > Third-Party IdP view in KaseyaOne.

  2. Configure the SSO settings in KaseyaOne for the third-party IdP integration. For this task, you will need the third-party IdP's Single Sign-On URL and SSO certificate.

  3. Assign users to the KaseyaOne application in your third-party IdP so that they will be able to use it.

  4. Test the third-party IdP SSO integration for KaseyaOne.

Example instructions follow in Third-party IdP SSO integrations using SAML 2.0 with KaseyaOne. The prerequisites to set up a third-party IdP integration with KaseyaOne are:

  • Master user account in KaseyaOne and Administrator account in the third-party IdP

  • Users must have the same email address in KaseyaOne and the third-party IdP

  • User/user groups must be set up in the third-party IdP

After you set up the third-party IdP integration, the next time you log in to KaseyaOne you will be prompted to select your preferred method to log in — sign in with Single Sign-On or with your KaseyaOne credentials, unless Require Log In with Single Sign-On is enabled. We recommend referring to your IdP's documentation when configuring this feature as they will provide the most up-to-date documentation for their platform.

Third-party IdP SSO integrations using SAML 2.0 with KaseyaOne

Set up third-party IdP SSO integrations with KaseyaOne:

Third-party IdPs that support SAML 2.0

A non-exhaustive list of third-party IdPs that support SAML 2.0 follows.