---
title: "SSO and Self-Service: technical factsheet"
slug: "sso-and-self-service-technical-factsheet"
updated: 2026-06-10T11:26:25Z
published: 2026-06-10T11:26:25Z
canonical: "help.cintra.co.uk/sso-and-self-service-technical-factsheet"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://help.cintra.co.uk/llms.txt
> Use this file to discover all available pages before exploring further.

# SSO and Self-Service: technical factsheet

<html><head></head><body><h2 data-block-id="mpvistzu-yrvnfd-174" id="introduction">Introduction</h2><p data-block-id="mpviwn1g-w7sbcl-416">This document specifies the requirements that a customer must meet in order to use <strong>Single Sign-On(SSO)</strong> feature within <strong>Self-Service</strong> together with integration and implementation details. <strong>SSO</strong> authentication in <strong>Self-Service</strong> is provided by <strong>SAML2</strong> federated authentication and all <strong>SSO</strong> integrations will require the customer to be familiar with <strong>SSO</strong> and <strong>SAML2</strong> concepts and terminology. &nbsp;<strong>Self-Service</strong> (the <strong>Service Provider/SP</strong>) has been tested and is in use with the most popular workplace <strong>Identity Provider (IdP)</strong> services - <a href="https://azure.microsoft.com/en-us/services/active-directory/" target="_blank" rel="noopener noreferrer">AzureAD</a>, <a href="https://www.okta.com/products/single-sign-on/" target="_blank" rel="noopener noreferrer">Okta</a>, <a href="https://www.onelogin.com/product/sso" target="_blank" rel="noopener noreferrer">OneLogin</a>, <a href="https://auth0.com/single-sign-on" target="_blank" rel="noopener noreferrer">Auth0</a> and on-prem <a href="https://docs.microsoft.com/en-us/windows-server/identity/active-directory-federation-services" target="_blank" rel="noopener noreferrer">ADFS</a>.</p><h2 data-block-id="mpvistzu-u50y08-175" id="background">Background</h2><p data-block-id="mpviwn1g-5409be-417"><strong>Self-Service</strong>has evolved to meet the demand for federated authentication and <strong>SAML2</strong> was chosen based on open standards and being well supported by the most widely used <strong>Identity Provider</strong> services. With the introduction of <strong>SSO</strong> capabilities in <strong>Self-Service</strong>, there has been no change to <strong>AD</strong> and standard username/password authentication capabilities. There is no requirement that all user accounts be <strong>SSO</strong>, <strong>Self-Service</strong> will accommodate a combination of <strong>SSO</strong>, <strong>AD</strong> and standard logins, however only one can be active at a time per user account.</p><p data-block-id="mpwgn3ub-5lrv69-001"><strong>Self-Service</strong>allows the customer to configure <strong>Self-Service</strong> for the initial <strong>SAML2</strong> data exchange and for any changes required after <strong>SSO</strong> go-live. This means configuration changes at the <strong>IdP</strong> can be immediately made in <strong>Self-Service</strong> by the customer. For example, a change to the <strong>IdP</strong> public certificate can be immediately uploaded in <strong>Self-Service</strong>. Cintra will provide the customer with <strong>System Administrator</strong> credentials which allows these updates and some other administrative changes to be made to <strong>Self-Service</strong>.</p><p data-block-id="mpwgn91q-kw5a4s-002"><strong>Self-Service</strong>is able to provide both <strong>SP</strong>-Initiated or <strong>IdP</strong>-initiated logins. Depending on their type of account, users can login via the <strong>Self-Service</strong> login page, or via an application dashboard provided by the customer's <strong>IdP</strong>.</p><p data-block-id="mpwgnd29-arzgz6-003">It should be noted that there are some intentional constraints that may differ from standard <strong>SAML2</strong> integrations. Some environments can allow a new <strong>IdP</strong> user to self-identify, and through various challenges, allow them to be matched to the application account. This is not the case in <strong>Self-Service</strong>. All users must be pre-provisioned in <strong>Self-Service</strong> before a federated login attempt will succeed. Also, we require a unique and immutable token to be stored against the <strong>IdP</strong> user profile and passed in the <strong>SAML2</strong> response to act as the unique identifier for the users identity.</p><h3 data-block-id="mpvistzv-k382o5-176" id="3-requirements">3. Requirements</h3><p data-block-id="mpviwn1g-tkaw7l-418">This section describes <strong>customer/IdP SAML2</strong> requirements to integrate with <strong>Self-Service</strong>.</p><h3 data-block-id="mpvistzv-f8vu6g-177" id="31-standard-saml2-requirements">3.1 Standard SAML2 Requirements.</h3><p data-block-id="mpviwn1g-9gg5t2-419">This list contains general requirements that are common in <strong>SAML2</strong> integrations.</p><div data-type="table-content"><table width="958" class="editor360-table fit-width" borderstyle="solid" style="max-width:958px;width:958px;"><colgroup><col style="width:479px;"><col style="width:479px;"></colgroup><tbody><tr><th colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviunma-27zgdg-237" style="text-align:center;">Ref No.</p></th><th colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviut94-o0f7cc-238" style="text-align:center;">Description</p></th></tr><tr><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviwn1h-29crw7-420"><span type="spanMark"><strong>1</strong></span></p></td><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviwn1h-u25p1e-421"><span type="spanMark">Create a new application in the IdP.</span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviwn1i-1uffnn-422"><span type="spanMark"><strong>2</strong></span></p></td><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviwn1i-tjqvzh-423"><span type="spanMark">Associate IdP users with the new IdP application.</span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviwn1i-0napi6-424"><span type="spanMark"><strong>3</strong></span></p></td><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviwn1i-90aalu-425"><span type="spanMark">Add the SP site metadata URL or enter SP SAML2 configuration data and base64 encoded public certificate to the IdP application.</span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviwn1i-ztcuu5-426"><span type="spanMark"><strong>4</strong></span></p></td><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviwn1i-4ndo6v-427"><span type="spanMark">Add the IdP metadata URL or enter IdP SAML2 configuration data and base64 encoded public certificate to the SP.</span></p></td></tr></tbody></table></div><h3 data-block-id="mpvistzw-rt2h31-178" id="32-selfservice-specific-requirements">3.2 Self-Service Specific Requirements</h3><p data-block-id="mpviwn1i-ksi8tp-428">This list contains requirements that are specific to <strong>Self-Service</strong>.</p><div data-type="table-content"><table width="958" class="editor360-table fit-width" borderstyle="solid" style="max-width:958px;width:958px;"><colgroup><col style="width:479px;"><col style="width:479px;"></colgroup><tbody><tr><th colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviuxar-3q0pvk-239" style="text-align:center;">Ref No.</p></th><th colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviuziu-lu2o5u-240" style="text-align:center;">Description</p></th></tr><tr><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviwn1j-9l12fc-429"><span type="spanMark"><strong>5</strong></span></p></td><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviwn1j-gq00wu-430"><span type="spanMark">Store a unique user identifier GUID against each users profile in the IdP. Attach the GUID as an attribute in the SAML response. </span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviwn1j-yv2jsx-431"><span type="spanMark"><strong>6</strong></span></p></td><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviwn1j-wgu415-432"><span type="spanMark">Select a user to test the integration with. Add the GUID to the users profile.</span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviwn1j-fq2ny3-433"><span type="spanMark"><strong>7</strong></span></p></td><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviwn1k-yxego0-434"><span type="spanMark">Populate a spreadsheet of users with their corresponding GUID. Upload spreadsheet to create accounts.</span></p></td></tr></tbody></table></div><h4 data-block-id="mpvistzx-wh2ns3-179" id="34-saml2-configuration-exchange-requirements"><span type="spanMark">3.4 SAML2 Configuration Exchange Requirements</span></h4><p data-block-id="mpviwn1k-hmp6r6-435"><strong>SAML2</strong>configuration data that should be made available by the <strong>IdP</strong>:</p><div data-type="table-content"><table width="958" class="editor360-table fit-width" borderstyle="solid" style="max-width:958px;width:958px;"><colgroup><col style="width:479px;"><col style="width:479px;"></colgroup><tbody><tr><th colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviv288-6a57x8-241" style="text-align:center;">Ref.</p></th><th colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviv3yn-sihvgd-242" style="text-align:center;">Description</p></th></tr><tr><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviwn1k-6s5gyd-436"><span type="spanMark"><strong>1</strong></span></p></td><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpvistzy-s6tdpr-180">IdP Entity ID</p></td></tr><tr><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviwn1l-60sy6u-437"><span type="spanMark"><strong>2</strong></span></p></td><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpvistzy-301cqz-181">IdP Sign On Service URL</p></td></tr><tr><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviwn1l-em2242-438"><span type="spanMark"><strong>3</strong></span></p></td><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpvistzy-09orts-182">IdP public signing certificate file (base64 cer file)</p></td></tr><tr><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviwn1l-thu67a-439"><span type="spanMark"><strong>4</strong></span></p></td><td colspan="1" rowspan="1" colwidth="479"><p dir="ltr" data-block-id="mpvistzz-b3clv8-183">SAML2 SP Metadata URL (optional)</p></td></tr></tbody></table></div><p data-block-id="mpviwn1l-b2ppqd-440"><strong>SAML2</strong>configuration data that is available in <strong>Self-Service</strong>:</p><div data-type="table-content"><table width="958" class="editor360-table fit-width" borderstyle="solid" style="max-width:958px;width:958px;"><colgroup><col style="width:479px;"><col style="width:479px;"></colgroup><tbody><tr><th colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviv733-9c4lmy-243" style="text-align:center;">Ref.</p></th><th colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviv96h-w758tp-244" style="text-align:center;">Description</p></th></tr><tr><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviwn1m-ykp698-441"><span type="spanMark"><strong>1</strong></span></p></td><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviwn1m-ggqxer-442">SAML2 SP Metadata URL</p></td></tr><tr><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviwn1m-xmastf-443"><span type="spanMark"><strong>2</strong></span></p></td><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpvistzz-r4t4iq-184">SP Entity ID, also known as Audience URI</p></td></tr><tr><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviwn1m-9ga6ji-444"><span type="spanMark"><strong>3</strong></span></p></td><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpvistzz-jexax4-185">SP Single Sign On URL, also known as Assertion Consumer Service or ACS URL</p></td></tr><tr><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviwn1n-rstnqq-445"><span type="spanMark"><strong>4</strong></span></p></td><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpvisu00-btnxwf-186">SP Single Logout URL</p></td></tr><tr><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpviwn1n-eqd3s0-446"><span type="spanMark"><strong>5</strong></span></p></td><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpvisu00-649mun-187">SP public signing certificate file (base64 cer file)</p></td></tr></tbody></table></div><h4 dir="ltr" data-block-id="mpvisu00-fni4g1-188" id="35-testing-requirements">3.5 Testing Requirements</h4><p data-block-id="mpviwn1n-vef70u-447">All <strong>SSO</strong> login testing is done on the production <strong>Self-Service</strong> web application.</p><p data-block-id="mpvivbn1-pvo5yh-246">This applies to new implementations and existing customers requiring some or all <strong>Self-Service</strong> users to move to <strong>SSO</strong> authentication.</p><p data-block-id="mpwgo89h-kw550q-004">Testing the <strong>SAML2</strong> configuration and validating the authentication involves setting up a single user with <strong>SSO</strong>. This nominated user should be someone who is readily available to perform authentication when needed. This user should be a real person (not a test account in the <strong>IdP</strong>), and is often a user from the customer's <strong>IT</strong>, <strong>Payroll</strong> or <strong>HR</strong> departments.</p><p data-block-id="mpwgocpe-pxpn8b-005">Unfortunately we cannot create temporary user account in <strong>Self-Service</strong> to test the <strong>SSO</strong> login. This is because all user accounts must be linked to real person data in <strong>Cintra iQ</strong>.</p><blockquote data-block-id="mpwgogkx-mejtxb-007" class="infoBox" data-background="#ddf7ff" data-border="#006a8a" style="background:rgb(221, 247, 255);border-left:4px solid rgb(0, 106, 138);overflow:auto;"><p data-block-id="mpwgofvm-oge02m-006"><strong>Note:</strong> For customers already using Self-Service: While testing with the nominated test user, all other existing non-SSO Self-Service users can continue to log in and use Self-Service as they normally would.</p></blockquote><h3 data-block-id="mpvisu00-hak75a-189" id="4-details-for-integration-with-selfservice">4. Details for Integration with Self-Service</h3><h4 data-block-id="mpvisu00-86pipz-190" id="41-typical-sso-implementation-checklist-for-a-new-customer">4.1 Typical SSO Implementation Checklist for a New Customer</h4><p data-block-id="mpviwn1n-2kwmqb-448">From <strong>Self-Service v76</strong>, customers are able to view and update the <strong>SAML2</strong> configuration data directly in <strong>Self-Service</strong>.</p><p data-block-id="mpvivgc9-7b13np-248">This list covers the steps that relate to only to <strong>SSO</strong>. Other steps will be required as part of a new customer implementation but have been omitted from this list.</p><div data-type="table-content"><table width="955" class="editor360-table fit-width" borderstyle="solid" style="max-width:955px;width:955px;"><colgroup><col style="width:191px;"><col style="width:191px;"><col style="width:191px;"><col style="width:191px;"><col style="width:191px;"></colgroup><tbody><tr><th colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpvivjcx-yibe4y-249" style="text-align:center;">Ref No.</p></th><th colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpvivne5-7dlhf3-250" style="text-align:center;">Description</p></th><th colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpvivnsc-bds8cy-251" style="text-align:center;">Who?</p></th><th colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpvivo65-wx8kvx-252" style="text-align:center;">Required/Optional</p></th><th colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpvivptr-33f7vo-253" style="text-align:center;">Ref.</p></th></tr><tr><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1o-99juli-449"><span type="spanMark"><strong>1</strong></span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1p-1jdfwu-450"><span type="spanMark">IQ and Self-Service site is provisioned</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1p-7bgf6p-451"><span type="spanMark">Cintra</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1p-axk6wn-452"><span type="spanMark">Required</span></p></td><td colspan="1" rowspan="1" colwidth="191"></td></tr><tr><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1p-wtfzxe-454"><span type="spanMark"><strong>2</strong></span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1q-d1wkmp-455"><span type="spanMark">IQ payroll data initialised (including employees)</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1q-vlnn05-456"><span type="spanMark">Cintra</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1q-uh0ho5-457"><span type="spanMark">Required</span></p></td><td colspan="1" rowspan="1" colwidth="191"></td></tr><tr><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1q-jrcbex-459"><span type="spanMark"><strong>3</strong></span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1r-5jiq2g-460"><span type="spanMark">Enable 'Employee Login ADFS' Web Feature License</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1r-w8s41v-461"><span type="spanMark">Cintra</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1r-ayqg9a-462"><span type="spanMark">Required</span></p></td><td colspan="1" rowspan="1" colwidth="191"></td></tr><tr><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1r-pe2r9r-464"><span type="spanMark"><strong>4</strong></span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1r-qtdlml-465"><span type="spanMark">Self-Service site URL and System Administrator account credentials provided to customer</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1r-3pw5wf-466"><span type="spanMark">Cintra</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1r-tblw2x-467"><span type="spanMark">Required</span></p></td><td colspan="1" rowspan="1" colwidth="191"></td></tr><tr><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1s-n4j1kz-469"><span type="spanMark"><strong>5</strong></span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1s-rcpm0n-470"><span type="spanMark">Self-Service SSO Setup Guide URL provided to customer</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1s-rocm27-471"><span type="spanMark">Cintra</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1s-25jtd0-472"><span type="spanMark">Required</span></p></td><td colspan="1" rowspan="1" colwidth="191"></td></tr><tr><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1s-cabhfr-474"><span type="spanMark"><strong>6</strong></span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1t-t3jsuu-475"><span type="spanMark">Enable SSO in Self-Service</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1t-ecflp1-476"><span type="spanMark">Customer</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1t-t6mm50-477"><span type="spanMark">Required</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1t-csgngf-478"><span type="spanMark">4.2</span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1t-mgk2oj-479"><span type="spanMark"><strong>7</strong></span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1t-osgmwi-480"><span type="spanMark">Agree the attribute name for the User Identifier GUID (or use the default)</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1t-bpyccr-481"><span type="spanMark">Customer/Cintra</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1u-ysj5i3-482"><span type="spanMark">Required</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1u-1q9tj5-483"><span type="spanMark">4.3</span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1u-w31ps2-484"><span type="spanMark"><strong>8</strong></span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1u-08btsh-485"><span type="spanMark">Create Self-Service SAML2 application in the IdP</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1u-qopzl7-486"><span type="spanMark">Customer</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1v-et3bpk-487"><span type="spanMark">Required</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1v-evhuay-488"><span type="spanMark">4.4</span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1v-7l81nh-489"><span type="spanMark"><strong>9</strong></span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1v-todow0-490"><span type="spanMark">Add the User Identifier GUID attribute to the IdP application</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1v-b2pwut-491"><span type="spanMark">Customer</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1v-24ekw3-492"><span type="spanMark">Required</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1v-oqjg45-493"><span type="spanMark">4.5</span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1v-4h4r15-494"><span type="spanMark"><strong>10</strong></span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1w-4rx7kc-495"><span type="spanMark">Enter IdP SAML2 configuration data in Self-Service</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1w-vfzdxa-496"><span type="spanMark">Customer</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1w-naqrs8-497"><span type="spanMark">Required</span></p></td><td colspan="1" rowspan="1" colwidth="191"></td></tr><tr><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1w-kzh7t2-499"><span type="spanMark"><strong>11</strong></span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1w-894ke3-500"><span type="spanMark">Alter SSO button appearance</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1w-nyyv7f-501"><span type="spanMark">Customer</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1w-ttxqhc-502"><span type="spanMark">Optional</span></p></td><td colspan="1" rowspan="1" colwidth="191"></td></tr><tr><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1x-xknjfg-504"><span type="spanMark"><strong>12</strong></span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1x-4537lg-505"><span type="spanMark">Generate &amp; add GUID to the nominated test users IdP profile</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1x-44s0fi-506"><span type="spanMark">Customer</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1x-2g4alf-507"><span type="spanMark">Required</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1x-9hd2ht-508"><span type="spanMark">4.6</span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1x-28vz25-509"><span type="spanMark"><strong>13</strong></span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1x-wz4rw4-510"><span type="spanMark">Create the test user SSO account in Self-Service</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1y-clbojf-511"><span type="spanMark">Customer</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1y-vbdftq-512"><span type="spanMark">Required</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1y-8qzr6o-513"><span type="spanMark"> 4.7</span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1y-bx0n0e-514"><span type="spanMark"><strong>14</strong></span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1y-00yjku-515"><span type="spanMark">Test user login attempt</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1y-chnyy6-516"><span type="spanMark">Customer</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1y-zf34rb-517"><span type="spanMark">Required</span></p></td><td colspan="1" rowspan="1" colwidth="191"></td></tr><tr><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1z-o290gc-519"><span type="spanMark"><strong>15</strong></span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1z-nc3vdn-520"><span type="spanMark">Evaluate failed test login attempt(s) in the Testing Error Log</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1z-ca8vm6-521"><span type="spanMark">Customer</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1z-3ax6ae-522"><span type="spanMark">Optional</span></p></td><td colspan="1" rowspan="1" colwidth="191"></td></tr><tr><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1z-o1ov4q-524"><span type="spanMark"><strong>16</strong></span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1z-ugazgp-525"><span type="spanMark">Generate/Link all remaining user GUID to IdP user profiles in the IdP</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn1z-4dav2k-526"><span type="spanMark">Customer</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn20-fl3ykm-527"><span type="spanMark">Required</span></p></td><td colspan="1" rowspan="1" colwidth="191"><p data-block-id="mpviwn23-dts25y-528"><span type="spanMark">4.8</span></p></td></tr></tbody></table></div><h4 data-block-id="mpvisu0b-aoybzz-191" id="42-enable-sso-in-selfservice">4.2 Enable SSO in Self-Service</h4><p data-block-id="mpvivvjd-8zun1j-254">By logging in to the <strong>Self-Service</strong> site with the <strong>System Administrator</strong> credentials and following the <strong>SSO Setup Guide</strong>, the customer can configure <strong>SSO</strong> to work with their <strong>IdP</strong>.</p><p data-block-id="mpvivwhv-th8dbh-255"><strong>Self-Service</strong>provides the information and certificates required by the <strong>IdP</strong> and also the ability to enter <strong>IdP</strong> configuration details.</p><h4 data-block-id="mpvisu0b-dywqr4-192" id="43-agree-the-attribute-name-for-the-user-identifier-guid">4.3 Agree the attribute name for the User Identifier GUID </h4><p data-block-id="mpviwn23-xv9tpg-529">Each <strong>SSO</strong> user account in <strong>Self-Service</strong> must be assigned a <strong>GUID</strong> generated by the customer. The <strong>GUID</strong> should be sent as an attribute in the <strong>SAML2</strong> Response message.</p><p data-block-id="mpviwn23-ka5lag-530"><span type="spanMark">The default <strong>SAML2</strong> attribute name is: </span><a href="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/privatepersonalidentifier" target="_blank" rel="noopener noreferrer"><span type="spanMark"><strong>http://schemas.xmlsoap.org/ws/2005/05/identity/claims/privatepersonalidentifier</strong></span></a></p><p data-block-id="mpviwn23-8n815j-531">The default attribute name and <strong>User Identifier GUID</strong> value as it appears in a <strong>SAML2</strong> Response message:<img data-block-id="mpvisu0b-wfn4k9-193" src="https://cdn.document360.io/fc2cda72-4645-4b36-96bf-60439ec11f11/Images/Documentation/204001065309.png" class="adv-wysiwyg-img" mediatype="img" alt="" width="auto" height="auto" dataalign="left" datadisplay="flex" data-type="media-content" fixaspectratio="false" autoaspectratio="false" shadow="no" border="no" round="no" link="" newtab="" style="width:auto;height:auto;"></p><p data-block-id="mpwgrj64-ty0oeo-008">If it's not possible for the <strong>IdP</strong> to use the default <strong>SAML2</strong> attribute name, then any other <strong>URI</strong> or simple string can be used. The following list shows examples of valid attribute names:</p><ol data-block-id="mpvisu0b-48oy3y-194" start="1" style="--start:0;"><li data-block-id="mpvisu0c-glboz4-195"><p data-block-id="mpviwn23-rqsqjw-532"><a href="https://yourcompany.org/saml2/attribute/uid" target="_blank" rel="noopener noreferrer">https://yourcompany.org/saml2/attribute/uid</a></p></li><li data-block-id="mpvisu0c-thpimq-196"><p data-block-id="mpviwn23-r3ehex-533">YourCompany.Attribute.UniqueIQ</p></li><li data-block-id="mpvisu0c-pa0hnt-197"><p data-block-id="mpviwn23-9m7c3k-534">self-service-unique-id</p></li><li data-block-id="mpvisu0c-03pgqv-198"><p data-block-id="mpviwn23-q4f7i0-535">CintraUID</p></li></ol><blockquote data-block-id="mpvisu0c-rrqj90-199" class="infoBox" data-background="#ddf7ff" data-border="#006a8a" style="background:rgb(221, 247, 255);border-left:4px solid rgb(0, 106, 138);overflow:auto;"><p dir="ltr" data-block-id="mpvisu0c-puasci-200">SAML2 attribute names are case sensitive.</p></blockquote><h4 dir="ltr" data-block-id="mpvisu0c-icinpl-201" id="44-create-selfservice-saml2-application-in-the-idp">4.4 Create Self-Service SAML2 Application in the IdP</h4><h4 data-block-id="mpvisu0c-gcb0mj-202" id="45-add-the-user-identifier-guid-attribute-to-the-idp-application">4.5 Add the User Identifier GUID attribute to the IdP application</h4><p data-block-id="mpviwn24-fyw7c3-536">The agreed <strong>GUID</strong> attribute will need to be added to the <strong>SAML2</strong> settings for the <strong>IdP</strong> application.</p><p data-block-id="mpvixati-6nzimq-576">This will allow the <strong>GUID</strong> set on the user's profile to be fetched and sent in the <strong>SAML2</strong> response.</p><p data-block-id="mpvixgak-o1686f-577">For example, the below screenshot shows the section within the <strong>SAML2</strong> settings of the application that allows this.</p><p data-block-id="mpviwn24-c936f9-537">The agreed attribute name is <strong>PPID</strong> (not the <strong>Self-Service</strong> default).</p><p data-block-id="mpviwn24-u8nu4w-538">The value being used is the <strong>user_guid</strong> parameter on the user profile. <img data-block-id="mpvisu0c-31wvua-203" src="https://cdn.document360.io/fc2cda72-4645-4b36-96bf-60439ec11f11/Images/Documentation/204001065310.png" class="adv-wysiwyg-img" mediatype="img" alt="" width="auto" height="auto" dataalign="left" datadisplay="flex" data-type="media-content" fixaspectratio="false" autoaspectratio="false" shadow="no" border="no" round="no" link="" newtab="" style="width:auto;height:auto;"></p><h4 data-block-id="mpvisu0c-1j7kdq-204" id="46-generate-and-add-guid-to-the-nominated-test-users-idp-profile">4.6 Generate and Add GUID to the Nominated Test User's IdP Profile</h4><p data-block-id="mpviwn24-jgnneb-539">The <strong>User IdentifierGUID</strong>s assigned to each user profile should follow a specific structure as defined in<a href="https://cdn.document360.io/fc2cda72-4645-4b36-96bf-60439ec11f11/Images/Documentation/rfc4122.txt" target="_blank" rel="noopener noreferrer">RFC 4122</a></p><p data-block-id="mpvixqk7-2oxrix-578">The format should be <strong>36</strong> characters (<strong>32</strong> hexadecimal characters and <strong>4</strong> hyphens) OR a <strong>base64</strong> encoded version of the <strong>GUID</strong>.</p><blockquote data-block-id="mpviybf1-0u3end-579" class="successBox" data-background="#c4f2d4" data-border="#029e38" style="background:rgb(196, 242, 212);border-left:4px solid rgb(2, 158, 56);overflow:auto;"><p data-block-id="mpvisu0c-znna7w-207"><strong>Examples of a valid User Identifier GUID values: </strong>123e4567-e89b-12d3-a456-426614174000 czEFTCp7b0SAZWhTOA717w==</p></blockquote><h3 data-block-id="mpvisu0c-3i3i0n-208" id="tools-for-generating-guids">Tools for generating GUIDs </h3><div data-type="table-content"><table width="957" class="editor360-table fit-width" borderstyle="solid" style="max-width:957px;width:957px;"><colgroup><col style="width:319px;"><col style="width:319px;"><col style="width:319px;"></colgroup><tbody><tr><th colspan="1" rowspan="1" colwidth="319"><p data-block-id="mpviwn24-cnn6ra-540" style="text-align:center;">OS/Language</p></th><th colspan="1" rowspan="1" colwidth="319"><p data-block-id="mpviwn25-9uwqvf-541" style="text-align:center;">Example Command</p></th><th colspan="1" rowspan="1" colwidth="319"><p data-block-id="mpviwn25-7t05r7-542" style="text-align:center;">Further Information</p></th></tr><tr><td colspan="1" rowspan="1" colwidth="319"><p data-block-id="mpviwn25-kvhucs-543"><strong>Windows (powershell)</strong></p></td><td colspan="1" rowspan="1" colwidth="319"><p data-block-id="mpviwn25-acux04-544">[guid]::NewGuid()</p></td><td colspan="1" rowspan="1" colwidth="319"><p data-block-id="mpviwn25-fcgxwl-545"><a href="https://devblogs.microsoft.com/scripting/powertip-create-a-new-guid-by-using-powershell/" target="_blank" rel="noopener noreferrer">PowerTip: Create a New GUID by Using PowerShell - Scripting Blog (microsoft.com)</a></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="319"><p data-block-id="mpviwn25-cbc0dc-546"><strong>Linux</strong></p></td><td colspan="1" rowspan="1" colwidth="319"><p data-block-id="mpviwn25-e8ova4-547">uuidgen</p></td><td colspan="1" rowspan="1" colwidth="319"><p data-block-id="mpviwn25-szmo5j-548"><a href="https://linoxide.com/how-to-generate-uuid-in-linux/" target="_blank" rel="noopener noreferrer">How to Generate UUID in Linux (linoxide.com)</a></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="319"><p data-block-id="mpviwn26-ecwjz0-549"><strong>Python 3</strong></p></td><td colspan="1" rowspan="1" colwidth="319"><p data-block-id="mpviwn26-dgmyr3-550">uuid.uuid4()</p></td><td colspan="1" rowspan="1" colwidth="319"><p data-block-id="mpviwn26-r6912x-551"><a href="https://docs.python.org/3/library/uuid.html#uuid.uuid4" target="_blank" translate="no" rel="noopener">uuid — UUID objects according to RFC 4122 — Python 3.10.2 documentation</a></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="319"><p data-block-id="mpviwn26-rmn7iz-552"><strong>C#</strong></p></td><td colspan="1" rowspan="1" colwidth="319"><p data-block-id="mpviwn26-oqitv8-553">Guid.NewGuid()</p></td><td colspan="1" rowspan="1" colwidth="319"><p data-block-id="mpviwn26-zm9jxn-554"><a href="https://learn.microsoft.com/en-us/dotnet/api/system.guid.newguid?view=net-6.0" target="_blank" translate="no" rel="noopener">Guid.NewGuid Method (System) | Microsoft Docs</a></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="319"><p data-block-id="mpviwn26-4ba8f5-555"><strong>Node JS </strong></p></td><td colspan="1" rowspan="1" colwidth="319"><p data-block-id="mpviwn26-p9d2vj-556">import { randomUUID } from 'crypto';const uuid = randomUUID();</p></td><td colspan="1" rowspan="1" colwidth="319"><p data-block-id="mpviwn26-7jy16m-557"><a href="https://futurestud.io/tutorials/how-to-generage-a-uuid-in-node-js" target="_blank" rel="noopener noreferrer">How to Generage a UUID in Node.js (futurestud.io)</a></p></td></tr></tbody></table></div><blockquote data-block-id="mpvisu0f-n5jzjf-209" class="errorBox" data-background="#f9e2e4" data-border="#7e1115" style="background:rgb(249, 226, 228);border-left:4px solid rgb(126, 17, 21);overflow:auto;"><p data-block-id="mpviwn27-uzjxgv-558"><strong>Warning: </strong> You should<span type="spanMark">not to use online GUID generation tools provided by unknown third parties</span></p></blockquote><p data-block-id="mpviwn27-qtaeu1-559">In <strong>AzureAD</strong> and <strong>ADFS/AD</strong> environments it is possible to link to the user's <strong>ObjectGUID</strong>, and use that as the User Identifier <strong>GUID</strong>. These are <strong>GUID</strong> values are created when <strong>AzureAD/AD</strong> objects are created and don't change during the life of the object.You should be aware that <strong>if you use the ObjectGUID for this purpose and need to move or recreate an AD User, their ObjectGUID will change and they will no longer be able to log in to Self-Service.</strong> To obtain the <strong>Object ID</strong> for an account, run this command against <strong>Azure Active Directory</strong> in<strong>PowerShell</strong></p><ol data-block-id="mpvisu0f-9yfco2-210" start="1" style="--start:0;"><li data-block-id="mpvisu0f-if06k1-211"><p data-block-id="mpviwn27-5hl82g-560">Connect-AzureAD</p></li><li data-block-id="mpvisu0f-outtb5-212"><p data-block-id="mpviwn27-ocifng-561">Get-AzureADUser -ObjectID "<a href="mailto:example.user@yourcompany.co.uk" target="_blank" rel="noopener noreferrer">example.user@yourcompany.co.uk</a>"</p></li></ol><blockquote data-block-id="mpvisu0f-ikb4qo-213" class="infoBox" data-background="#ddf7ff" data-border="#006a8a" style="background:rgb(221, 247, 255);border-left:4px solid rgb(0, 106, 138);overflow:auto;"><p data-block-id="mpviwn27-4nvwj2-562"><strong>Note: </strong> Please be sure to replace the email address in line two. Also please check the email corresponds exactly to the email of the user doing the SAML2 login test.</p></blockquote><p data-block-id="mpviwn27-a5egvs-563">Once you have created or obtained the <strong>GUID</strong>, it should be added to the test users profile in the <strong>IdP</strong> to make it available for the <strong>SAML2</strong> attribute.</p><h4 dir="ltr" data-block-id="mpvisu0f-o9y5wm-214" id="47-create-the-test-user-in-selfservice">4.7 Create the Test User in Self-Service</h4><p data-block-id="mpviwn27-lq1znd-564">Create the test user using full name, email address and the <strong>GUID</strong>.</p><h4 data-block-id="mpvisu0g-9s2d8u-215" id="48-generatelink-all-remaining-required-user-guids-to-idp-user-profiles">4.8 Generate/Link all Remaining Required User GUIDs to IdP User Profiles</h4><p data-block-id="mpviwn27-pmdyjf-565">For each user required to have <strong>SSO</strong> logins created, create or obtain <strong>GUID</strong>s for each of them and add them to each users <strong>IdP</strong> profile.</p><p data-block-id="mpvizfxl-a67lh8-580">If <strong>SSO</strong> logins are not required for some of the users, please advise your <strong>Implementation Consultant</strong> which of your users you require traditional (username/password) logins created for.</p><h4 data-block-id="mpvisu0g-9qf7e7-216" id="49-populate-guids-in-the-bulk-account-creation-spreadsheet">4.9 Populate GUIDs in the Bulk Account Creation Spreadsheet</h4><p data-block-id="mpviwn27-09qpyw-566">For each user that is required to have an <strong>SSO</strong> account creating for, please enter the <strong>GUID</strong> value in column <strong>F (SSO/SAML2 GUID)</strong>. The spreadsheet will look similar to the following:<img data-block-id="mpvisu0g-lcyree-217" src="https://cdn.document360.io/fc2cda72-4645-4b36-96bf-60439ec11f11/Images/Documentation/204001065311.png" class="adv-wysiwyg-img" mediatype="img" alt="" width="auto" height="auto" dataalign="left" datadisplay="flex" data-type="media-content" fixaspectratio="false" autoaspectratio="false" shadow="no" border="no" round="no" link="" newtab="" style="width:auto;height:auto;">For each user that do not require an <strong>SSO</strong> login created for, please leave the <strong>GUID</strong> cell empty in that row.</p><p data-block-id="mpvizmvi-o049d9-581">Also leave the <strong>GUID</strong> cell empty if it's been requested that the user will have a standard username/password login.</p><p data-block-id="mpwh3qw7-2p0am5-015">It can be more efficient to export a dataset from the <strong>IdP</strong> user store that includes the <strong>GUID</strong> and using populate the <strong>GUID</strong> column using <strong>Excel</strong> functions/features. Once this spreadsheet is complete, please arrange to send it securely to your Implementation <strong>Consultant</strong>.</p><h3 data-block-id="mpvisu0g-t20koj-218" id="5-configuration-using-metadata">5. Configuration Using Metadata </h3><p data-block-id="mpviwn27-5tz6k5-567">The most convenient way to exchange <strong>SAML2</strong> configuration data is by using metadata. This is also the most reliable as it reduces the chance of typing or copy/paste errors.</p><p data-block-id="mpvizoof-si359y-582">In the <strong>SSO Settings</strong> area of <strong>Self-Service</strong>, all relevant <strong>SP</strong> data is shown including the metadata <strong>URL</strong>.</p><p data-block-id="mpvizx0o-mut7or-583">Once the <strong>IdP</strong> application is created, some <strong>IdP</strong> services can also provide a metadata <strong>URL</strong>. Within <strong>Self-Service</strong> this can be pasted and parsed to extract the <strong>IdP</strong> settings.</p><p data-block-id="mpvj01mz-07zehy-584">If an <strong>IdP</strong> metadata <strong>URL</strong> is not available, there are text boxes for the values to be entered manually.</p><h3 data-block-id="mpvisu0g-lo4mlv-219" id="6-certificates">6. Certificates</h3><h4 data-block-id="mpvisu0g-o3e7o5-220" id="61-signing-and-encryption">6.1 Signing and Encryption</h4><p data-block-id="mpviwn28-iubpen-568"><strong>Self-Service DOES </strong>require <strong>SAML2</strong> messages to be signed.</p><p data-block-id="mpvj06fx-7l2ts8-585"><strong>Self-Service DOES NOT</strong>require <strong>SAML2</strong> messages to be encrypted.</p><p data-block-id="mpwgt2p1-ktjbvc-009">When <strong>SSO</strong> is enabled in <strong>Self-Service</strong>, a private/public keypair for signing <strong>SAML2</strong> messages is created. This certificate has a <strong>10 year expiry date</strong>.</p><p data-block-id="mpvj0do2-swelso-586"><strong>Self-Service</strong>includes the <strong>X509</strong> public signing certificate within the metadata content and also makes it available separately for download if required.</p><p data-block-id="mpwgtbky-inlibe-010">If using <strong>IdP</strong> metadata, the metadata content should include the <strong>X509</strong> public signing certificate for the <strong>IdP</strong>.</p><p data-block-id="mpvj0jgx-xcr0j6-587">If not using the <strong>IdP</strong> metadata, the <strong>IdP</strong> public certificate file will be required and can be uploaded in <strong>Self-Service</strong>.</p><h4 data-block-id="mpvisu0g-2j8xs3-221" id="62-certificate-security">6.2 Certificate Security</h4><p data-block-id="mpviwn28-7f10kd-569">It is good practice to check the certificate fingerprint/thumbprint is as expected, to give extra assurance that the certificate hasn’t been tampered with.</p><p data-block-id="mpvj0mat-g7yeym-588">The check should be done using a different method to the one used to send the certificate. For example, if the certificate is emailed, don't use email to send the thumbprint string.</p><p data-block-id="mpwh4m34-tdz04w-017">The same process should be followed when any of the certificates or metadata are refreshed.</p><h4 data-block-id="mpvisu0g-jch4mq-222" id="63-refreshing-certificates-and-metadata">6.3 Refreshing Certificates and Metadata</h4><p data-block-id="mpviwn28-fujv51-570">Any configuration changes to certificates and metadata within the <strong>Idp</strong> or <strong>Self-Service</strong> should be managed by the customer.</p><p data-block-id="mpvj0poj-0qms0o-589">On the <strong>Self-Service</strong> side it is possible to generate a new signing certificate at any time. However, with a 10 year expiry, this won't be required often.</p><p data-block-id="mpwgtorf-62ica4-011">If, after a new signing certificate is created, the <strong>IdP</strong> is using and is monitoring the <strong>Self-Service</strong> metadata <strong>URL</strong>, then service may continue uninterupted.</p><p data-block-id="mpvj0vtu-3ygbb2-590">However, if not, the <strong>Self-Service</strong> public signing certificate will need to be downloaded and updated in the <strong>IdP</strong>.</p><p data-block-id="mpwgttew-clwr87-012">Any changes to certificates and/or metadata at the <strong>IdP</strong> side will need to be updated within <strong>Self-Service</strong>.</p><p data-block-id="mpvj0xzi-ye6lo4-591">Even though the <strong>IdP</strong> metadata <strong>URL</strong> can be entered in <strong>Self-Service</strong>, the values are only parsed, the endpoint is not monitored for changes.</p><blockquote data-block-id="mpvisu0g-437p27-223" class="infoBox" data-background="#ddf7ff" data-border="#006a8a" style="background:rgb(221, 247, 255);border-left:4px solid rgb(0, 106, 138);overflow:auto;"><p dir="ltr" data-block-id="mpvisu0g-497y9x-224">Self-Service does NOT monitor the IdP metadata URL for changes.</p></blockquote><h3 data-block-id="mpvisu0g-xxq8tn-225" id="7-common-questions">7. Common Questions</h3><h4 data-block-id="mpvisu0g-f6oe5e-226" id="71-why-do-you-use-a-guid-and-not-the-users-email-address">7.1 Why do you use a GUID and not the user’s email address?</h4><p data-block-id="mpviwn28-vr8sdr-571">The nature of the information within the <strong>Self-Service</strong> application is highly personal to each user - PII, salary/pay, sickness information, etc.</p><p data-block-id="mpwgu219-2zpdur-013">Therefore, we need to ensure that the <strong>Self-Service</strong> account is matched correctly after authentication, and reduce the chance of a person being given access to the wrong account.</p><p data-block-id="mpwgu5al-rhvh8n-014">Email addresses allocated to a person can change, or be assigned to different people over time.</p><p data-block-id="mpvj1bdo-f7hyoc-592">Here are some examples of when this occurs:</p><ol data-block-id="mpvisu0g-wig374-227" start="1" style="--start:0;"><li data-block-id="mpvisu0g-crg4gm-228"><p data-block-id="mpviwn28-4j9vbp-572">Email addresses can contain department specific information and may change as people move within a company/organisation.</p></li><li data-block-id="mpvisu0g-xqbxx4-229"><p data-block-id="mpviwn28-1pgp19-573">Email addresses can be changed when people change their name i.e. after marriage.</p></li><li data-block-id="mpvisu0g-477wj9-230"><p data-block-id="mpviwn28-lfhefm-574">Email addresses can also be recycled when leavers and joiners share the same name.</p></li></ol><p data-block-id="mpviwn28-xl49h2-575">Each change would need to have a corresponding change in <strong>Self-Service</strong> and the frequency of these changes often depends on the type or size of the organisation.</p><p data-block-id="mpvj1je4-p7ur7k-593">Another reason email is unsuitable relates to email addresses appearing to represent someone’s identity, and the chance of human error.</p><p data-block-id="mpvj1ob4-6ikgy3-594">Email addresses conveniently assume an association to a real person, most of the time it seems obvious who ‘owns’ an email address from the names included in the address, but unfortunately company or organisation email is not reliable enough to be used for identity purposes. To illustrate, in larger companies, where several staff are employed with the same name, or very close names, the association to a real person becomes less obvious.</p><p data-block-id="mpvj1ryt-y3bexp-595">E.g. <a href="mailto:stephen.smith@xyz.com" target="_blank" rel="noopener noreferrer">stephen.smith@xyz.com</a>, <a href="mailto:steve.smith@xyz.com" target="_blank" rel="noopener noreferrer">steve.smith@xyz.com</a> and <a href="mailto:steven.smith@xyz.com" target="_blank" rel="noopener noreferrer">steven.smith@xyz.com</a>. The consequences aren’t too significant when selecting an email address to send an email to, but for account matching in <strong>SSO</strong>, getting the right email is critical to make sure access to the correct <strong>Self-Service</strong> account is given.</p><p data-block-id="mpvj1w51-2mrz10-596">The <strong>GUID</strong> is naturally unique and immutable, and it doesn’t appear to represent an identity, but it can be easily linked to an identity in the <strong>Identity Provider (IdP)</strong> user store. A <strong>GUID</strong> is less likely to be given to someone else by accident and won't break the application if a person’s profile data (including email) is changed in the <strong>IdP</strong>.</p><p data-block-id="mpvj1zdq-zbgxqg-597">There is effort required in setting up the new GUIDs for each user during implementation and for new staff, but for the reasons and risks stated we aren't able to use email or any other data as the user identifier.</p></body></html>
