---
title: "SSO setup guide for Self-Service"
slug: "sso-setup-guide-for-self-service"
updated: 2026-06-10T11:26:25Z
published: 2026-06-10T11:26:25Z
canonical: "help.cintra.co.uk/sso-setup-guide-for-self-service"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://help.cintra.co.uk/llms.txt
> Use this file to discover all available pages before exploring further.

# SSO setup guide for Self-Service

<html><head></head><body><p data-block-id="mpvj22ok-6oztx8-052">Before you begin: Please read the SSO and Self Service - Technical Factsheet to see the background and requirements needed for a successful integration.</p><p dir="ltr" data-block-id="mpvj22ok-4f9x8b-053">Remember that instead of creating a new account for SSO for returning employees, you should edit their existing one.</p><h2 dir="ltr" data-block-id="mpvj22om-1t6kza-076" id="introduction">Introduction</h2><p data-block-id="mpvj22om-y8vbb3-077">This document specifies the steps required to set up SSO in Self-Service. SSO authentication in Self-Service is provided by SAML2 federated authentication and all SSO integrations will require the customer to have a technical resource that is familiar with SSO and SAML2 concepts and terminology.</p><p data-block-id="mpvj22om-u4u44g-078">Setting up SSO in Self-Service has been designed so that most of the initial configuration and any ongoing changes can be carried out by the customer. Therefore, this guide is written with the customer as the intended audience.</p><h3 data-block-id="mpvj22om-3ybc54-079" id="new-customer-implementation-checklist">New Customer Implementation Checklist</h3><p data-block-id="mpwh5t8f-ikwxdc-153">The steps carried out by Cintra and the customer are included in this checklist - the steps required to be performed by the customer are highlighted in <strong>bold</strong>.</p><p data-block-id="mpwhf5x1-0dz3dm-015">This list covers the steps that relate to only to SSO.</p><p data-block-id="mpwhf8qs-vpb5kw-016">Other steps will be required as part of a new customer implementation but have been omitted from this list.</p><div data-type="table-content"><table width="956" class="editor360-table fit-width" borderstyle="solid" style="max-width:956px;width:956px;"><colgroup><col style="width:239px;"><col style="width:239px;"><col style="width:239px;"><col style="width:239px;"></colgroup><tbody><tr><th colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpwh5t8f-v6vnxn-154" style="text-align:center;">Step</p></th><th colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpwh5t8f-q51rqa-155" style="text-align:center;">Description</p></th><th colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpwh5t8g-x6rqm4-156" style="text-align:center;">Who?</p></th><th colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpwh5t8g-cj3b76-157" style="text-align:center;">Required/Optional</p></th></tr><tr><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22on-jps3qy-080"><span type="spanMark"><span type="spanNode">1</span></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22on-r6kcj1-081"><span type="spanMark"><span type="spanNode">IQ and Self-Service site is provisioned</span></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22on-5ha50e-082"><span type="spanMark"><span type="spanNode">Cintra</span></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22on-36j95v-083"><span type="spanMark"><span type="spanNode">Required</span></span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22oo-ketvtu-084"><span type="spanMark"><span type="spanNode">2</span></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22oo-p875dt-085"><span type="spanMark"><span type="spanNode">IQ payroll data initialised (including employees)</span></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22oo-dm2gsr-086"><span type="spanMark"><span type="spanNode">Cintra</span></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22oo-ih31r7-087"><span type="spanMark"><span type="spanNode">Required</span></span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22oo-s4gyfa-088"><span type="spanMark"><span type="spanNode">3</span></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22oo-i4ekh8-089"><span type="spanMark"><span type="spanNode">Enable 'Employee Login ADFS' Web Feature License</span></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22oo-3ooovk-090"><span type="spanMark"><span type="spanNode">Cintra</span></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22op-s5m9z2-091"><span type="spanMark"><span type="spanNode">Required</span></span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22op-z1atxl-092"><span type="spanMark"><span type="spanNode">4</span></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22op-pccii8-093"><span type="spanMark"><span type="spanNode">Self-Service site URL and System Administrator account credentials provided to customer</span></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22op-ir263p-094"><span type="spanMark"><span type="spanNode">Cintra</span></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22op-49qag8-095"><span type="spanMark"><span type="spanNode">Required</span></span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22op-37wxjg-096"><span type="spanMark"><span type="spanNode">5</span></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22op-yjlndg-097"><span type="spanMark"><span type="spanNode">Ensure Self-Service SSO Technical Factsheet &amp; SSO Setup Guide URL are provided to customer</span></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22op-86wujz-098"><span type="spanMark"><span type="spanNode">Cintra</span></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22oq-9wxi4x-099"><span type="spanMark"><span type="spanNode">Required</span></span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22oq-a52mic-100"><span type="spanMark"><strong>6</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22oq-u2ptl3-101"><span type="spanMark"><strong>Enable SSO in Self-Service</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22oq-ty3pyc-102"><span type="spanMark"><strong>Customer</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22oq-yivddv-103"><span type="spanMark"><strong>Required</strong></span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22oq-f4ob4n-104"><span type="spanMark"><strong>7</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22oq-jmseit-105"><span type="spanMark"><strong>Agree the attribute name for the User Identifier GUID (or use the default)</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22oq-3sivn8-106"><span type="spanMark"><strong>Both</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22oq-5i4sja-107"><span type="spanMark"><strong>Required</strong></span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22or-8x4egc-108"><span type="spanMark"><strong>8</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22or-kfrn73-109"><span type="spanMark"><strong>Create Self-Service SAML2 application in the IdP</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22or-vxc1j1-110"><span type="spanMark"><strong>Customer</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22or-lrg7ag-111"><span type="spanMark"><strong>Required</strong></span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22or-vst91i-112"><span type="spanMark"><strong>9</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22or-ivn3i2-113"><span type="spanMark"><strong>Add the User Identifier GUID attribute to the IdP application</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22or-isnm3v-114"><span type="spanMark"><strong>Customer</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22or-ost3pf-115"><span type="spanMark"><strong>Required</strong></span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22or-e6kmvg-116"><span type="spanMark"><strong>10</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22os-0pzxnw-117"><span type="spanMark"><strong>Enter IdP SAML2 configuration data in Self-Service</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22os-gzkeyo-118"><span type="spanMark"><strong>Customer</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22os-4wo3pf-119"><span type="spanMark"><strong>Required</strong></span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22os-ouz47b-120"><span type="spanMark"><strong>11</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22os-vn7x6u-121"><span type="spanMark"><strong>Alter SSO button appearance</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22os-syhwxd-122"><span type="spanMark"><strong>Customer</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22os-enfr9n-123"><span type="spanMark"><strong>Optional</strong></span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22os-xubdfx-124"><span type="spanMark"><strong>12</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22os-1pxgml-125"><span type="spanMark"><strong>Generate &amp; add GUID to the nominated test users IdP profile</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22ot-g85sc9-126"><span type="spanMark"><strong>Customer</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22ot-rhemrq-127"><span type="spanMark"><strong>Required</strong></span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22ot-wpwn9l-128"><span type="spanMark"><strong>13</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22ot-dmvdkg-129"><span type="spanMark"><strong>Provide the test user GUID to Cintra</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22ot-aqoazr-130"><span type="spanMark"><strong>Customer</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22ot-83qypw-131"><span type="spanMark"><strong>Required</strong></span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22ot-rit7tv-132"><span type="spanMark"><span type="spanNode">14</span></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22ot-h7ryxs-133"><span type="spanMark"><span type="spanNode">Create the test user SSO account in Self-Service</span></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22ot-p6t4az-134"><span type="spanMark"><span type="spanNode">Cintra</span></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22ou-iajza7-135"><span type="spanMark"><span type="spanNode">Required</span></span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22ou-cvgsck-136"><span type="spanMark"><strong>15</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22ou-ae50ks-137"><span type="spanMark"><strong>Test user login attempt</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22ou-4am8o6-138"><span type="spanMark"><strong>Customer</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22ou-nxx70w-139"><span type="spanMark"><strong>Required</strong></span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22ou-okx753-140"><span type="spanMark"><strong>16</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22ou-z8dkfd-141"><span type="spanMark"><strong>Evaluate failed test login attempt(s) in the Testing Error Log</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22ou-wmqbt5-142"><span type="spanMark"><strong>Customer</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22ou-9ruz1j-143"><span type="spanMark"><strong>Optional</strong></span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22ov-kxlb38-144"><span type="spanMark"><strong>17</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22ov-veb1c5-145"><span type="spanMark"><strong>Generate/Link all remaining user GUID to IdP user profiles in the IdP</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22ov-i4xmd8-146"><span type="spanMark"><strong>Customer</strong></span></p></td><td colspan="1" rowspan="1" colwidth="239"><p data-block-id="mpvj22ov-1c05os-147"><span type="spanMark"><strong>Required</strong></span></p></td></tr></tbody></table></div><p data-block-id="mpwh5t90-rc3tx0-158">For existing customers already using <strong>Self-Service</strong>, this checklist can be followed up to step <strong>17</strong> with the following amendments:</p><ol data-block-id="mpvj22ov-puwuvn-148" start="1" style="--start:0;"><li data-block-id="mpvj22ov-t52omw-149"><p data-block-id="mpwh5t91-q0885d-159">Steps <strong>1 &amp; 2</strong> are not required and can be omitted.</p></li><li data-block-id="mpvj22ov-ksa8hp-150"><p data-block-id="mpwh5t91-tgj7cs-160">Step<strong> 14</strong> (actioned by Cintra). If the test user already exists with a <strong>Self-Service</strong> account, they need to be changed to an <strong>SSO</strong> login</p></li></ol><h2 data-block-id="mpvj22ov-xv0llt-151" id="so-setup-process">SO Setup Process</h2><h3 data-block-id="mpvj22ov-358x62-152" id="1-5-actioned-by-cintra">1 - 5. <span type="spanMark">Actioned By Cintra</span></h3><ol data-block-id="mpvj22ov-9l4ppd-153" start="1" style="--start:0;"><li data-block-id="mpvj22ov-9wcqz3-154"><p data-block-id="mpwh5t91-drizxz-161">IQ and Self-Service site is provisioned.</p></li><li data-block-id="mpvj22ov-2ttq4p-155"><p data-block-id="mpwh5t91-8za298-162"><span type="spanMark"><span type="spanNode">IQ payroll data is initialised (including employees)</span></span></p></li><li data-block-id="mpvj22ov-dz65ev-156"><p data-block-id="mpwh5t91-f5q1dz-163"><span type="spanMark"><span type="spanNode">Web Feature License is enabled. </span></span></p></li><li data-block-id="mpvj22ov-v615sv-157"><p data-block-id="mpwh5t91-nevika-164">To securely provide the customer the <strong>Self-Service</strong> web application <strong>URL</strong> and <strong>System Administrator</strong> login credentials.</p></li><li data-block-id="mpvj22ov-5o06xp-158"><p data-block-id="mpwh5t91-yn98wg-165">To ensure the customer has been given <strong>SSO</strong> setup documentation.</p></li></ol><h3 data-block-id="mpvj22ov-lno3sv-159" id="6-enable-the-sso-feature-within-selfservice">6. Enable the SSO feature within Self-Service</h3><ol data-block-id="mpvj22ov-vg1yq9-160" start="1" style="--start:0;"><li data-block-id="mpvj22ov-rbjvl8-161"><p data-block-id="mpwh5t91-uhr3wc-166">In a browser, visit the <strong>Self-Service</strong> application <strong>URL</strong> provided at step <strong>4</strong>.</p></li><li data-block-id="mpvj22ow-uxreth-162"><p data-block-id="mpwh5t91-kzfqcq-167">Log in using the <strong>System Administrator</strong> credentials provided at step <strong>4</strong>.</p></li><li data-block-id="mpvj22ow-aeutp7-163"><p data-block-id="mpwh5t91-5k87rg-168">Once logged, in the left navigation menu, go to <strong><em>Configuration</em></strong> &gt; <strong><em>SSO Settings</em></strong>. (If the navigation menu is not visible - as in <strong>fig.1</strong> below, use the top-left 3-line '<strong>hamburge</strong>r' icon to show the navigation menu.)</p></li><li data-block-id="mpvj22ow-w3vrw2-164"><p data-block-id="mpwh5t91-9r7u3f-169">You will see the following screen. Click the <strong>Enable SSO</strong> button.<strong><em></em></strong><img data-block-id="mpvj22ow-7xevo7-165" src="https://cdn.document360.io/fc2cda72-4645-4b36-96bf-60439ec11f11/Images/Documentation/204001065314.png" class="adv-wysiwyg-img" mediatype="img" alt="" width="auto" height="auto" dataalign="left" datadisplay="flex" data-type="media-content" fixaspectratio="false" autoaspectratio="false" shadow="no" border="no" round="no" link="" newtab="" style="width:auto;height:auto;"></p></li><li data-block-id="mpvj22ow-3g77ur-170"><p data-block-id="mpwh5t92-75k12b-170"><strong>SSO </strong>will be enabled, the page will refresh and you will see a screen similar to the following:<img data-block-id="mpvj22ow-az849d-171" src="https://cdn.document360.io/fc2cda72-4645-4b36-96bf-60439ec11f11/Images/Documentation/204001065315.png" class="adv-wysiwyg-img" mediatype="img" alt="" width="auto" height="auto" dataalign="left" datadisplay="flex" data-type="media-content" fixaspectratio="false" autoaspectratio="false" shadow="no" border="no" round="no" link="" newtab="" style="width:auto;height:auto;"></p></li></ol><h3 data-block-id="mpvj22ow-4gex2o-172" id="7-agree-the-attribute-name-for-the-user-identifier-guid">7. Agree the attribute name for the User Identifier GUID</h3><p data-block-id="mpwh5t92-239qqq-171">By default, <strong>Self-Service</strong> reads the <strong>SAML2</strong> attribute for the <strong>User Identifier GUID</strong> from this attribute:</p><p data-block-id="mpwhgj2r-ikgvsq-017"><strong>http://schemas.xmlsoap.org/ws/2005/05/identity/claims/privatepersonalidentifier</strong></p><blockquote data-block-id="mpvj22ox-1ey4bt-173" class="infoBox" data-background="#ddf7ff" data-border="#006a8a" style="background:rgb(221, 247, 255);border-left:4px solid rgb(0, 106, 138);overflow:auto;"><p dir="ltr" data-block-id="mpvj22ox-b2ou1q-174">This is a <a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/technical-reference/the-role-of-claims#what-are-claim-types" target="_blank" rel="noopener noreferrer">Microsoft claim URI</a> and not a URL for use in a web browser.</p></blockquote><p data-block-id="mpwh5t92-dlz2ax-172">If you'll be sending the <strong>User Identifier GUID</strong> in a different <strong>SAML2</strong> attribute, an update to <strong>Self-Service</strong> will be required and this can be done in step <strong>10</strong>.</p><p data-block-id="mpwhhcui-uxdzc7-018">If you are using the default attribute, no additional update to <strong>Self-Service</strong> is required.</p><h3 data-block-id="mpvj22ox-of700z-175" id="8-create-selfservice-saml2-application-in-the-idp">8. Create Self-Service SAML2 application in the IdP</h3><p data-block-id="mpwh5t93-ommdz1-173">With the <strong>Service Provider/SP SAML2</strong> information provided on the '<strong>1. Self-Service Information</strong>' tab within <strong>SSO Settings</strong> of <strong>Self-Service</strong> (fig. 2 above), you should have sufficient information to create the <strong>IdP SAML2</strong> application.</p><h3 data-block-id="mpvj22ox-cey8pr-176" id="9-add-the-user-identifier-guid-attribute-to-the-idp-application">9. Add the User Identifier GUID attribute to the IdP application</h3><p data-block-id="mpwh5t93-6zz453-174">The agreed <strong>User Identifier GUID</strong> attribute (from step 7) will need to be added to the <strong>SAML2</strong> settings for the <strong>IdP</strong> application. This will allow the <strong>GUID</strong> set on the user's profile to be fetched and sent in the <strong>SAML2</strong> response.</p><p data-block-id="mpwhhk9y-1mvves-019">For example, if using <a href="https://okta.com/" target="_blank" rel="noopener noreferrer">Okta</a> as the <strong>IdP</strong>, the below screenshot shows the section within the <strong>SAML2</strong> settings of the application that allows this.</p><p data-block-id="mpwhhoht-708joc-020">In this example, the agreed attribute name is <strong>PPID</strong> (not the <strong>Self-Service</strong> default).</p><p data-block-id="mpwh5t93-8fuz43-175">The value being used is the<strong> user_guid</strong> parameter on the user profile.<img data-block-id="mpvj22ox-9j8m8o-177" src="https://cdn.document360.io/fc2cda72-4645-4b36-96bf-60439ec11f11/Images/Documentation/204001065316.png" class="adv-wysiwyg-img" mediatype="img" alt="" width="auto" height="auto" dataalign="left" datadisplay="flex" data-type="media-content" fixaspectratio="false" autoaspectratio="false" shadow="no" border="no" round="no" link="" newtab="" style="width:auto;height:auto;"></p><h3 data-block-id="mpvj22ox-qyu5m7-178" id="10-enter-idp-saml2-configuration-data-in-selfservice">10. Enter IdP SAML2 configuration data in Self-Service</h3><p data-block-id="mpwh5t94-1i5k5p-176">Once the <strong>SAML2</strong> application is created in the <strong>IdP</strong>, the <strong>SAML2</strong> settings required by <strong>Self-Service</strong> should be available.</p><p data-block-id="mpwh7omr-102u1v-206">These values should be entered into <strong>Self-Service</strong> in the '<strong>2. SAML2 Settings</strong>' tab within <strong>SSO Settings</strong>.</p><div class="image-view-figure"><figure data-block-id="mpwh7hty-oq39er-202" class="figure" dataalign="left" datadisplay="flex" style="width:979.609px;"><img data-block-id="mpwh7elz-f50xsh-201" src="https://cdn.document360.io/fc2cda72-4645-4b36-96bf-60439ec11f11/Images/Documentation/204001065317.png" class="adv-wysiwyg-img" mediatype="img" alt="" width="auto" height="auto" dataalign="left" datadisplay="flex" data-type="media-content" fixaspectratio="false" autoaspectratio="false" shadow="no" border="no" round="no" link="" newtab="" style="width:auto;height:auto;"><figcaption data-block-id="mpwh7hty-6abeo5-203"><p data-block-id="mpwh7hty-44tw9u-204"><em>fig.3: SSO Settings - SAML2 Settings Tab</em></p></figcaption></figure></div><h3 data-block-id="mpvj22ox-pxruyn-180" id="enter-the-idp-saml2-settings">Enter the IdP SAML2 settings</h3><p data-block-id="mpvj22ox-te5lsd-181">Values can be extracted from an <strong>IdP</strong> metadata endpoint <strong>URL</strong>, if the <strong>IdP</strong> provides one, or the three <strong>IdP</strong> values and the public certificate can be added/uploaded manually.</p><blockquote data-block-id="mpvj22ox-tvmp16-182" class="infoBox" data-background="#ddf7ff" data-border="#006a8a" style="background:rgb(221, 247, 255);border-left:4px solid rgb(0, 106, 138);overflow:auto;"><p dir="ltr" data-block-id="mpvj22ox-o6nz09-183">Self-Service does not monitor the IdP metadata URL for changes. Changes to any of the SAML2 values or the certificate in the IdP will require the details to be updated in this tab.</p></blockquote><p dir="ltr" data-block-id="mpvj22ox-b1xu6q-184">If using the metadata endpoint:</p><ul data-block-id="mpvj22ox-a8ti29-185"><li data-block-id="mpvj22ox-4ej863-186"><p data-block-id="mpwh5t95-qekhgi-177">Enter the <strong>Metadata URL </strong>and click <strong>Extract Settings</strong>. The required values will be extracted and the <strong>IdP</strong> fields will be populated, including the <strong>IdP Public Certificate</strong> if present in the metadata.</p></li></ul><blockquote data-block-id="mpvj22ox-tgjdfd-187" class="infoBox" data-background="#ddf7ff" data-border="#006a8a" style="background:rgb(221, 247, 255);border-left:4px solid rgb(0, 106, 138);overflow:auto;"><p data-block-id="mpwh5t96-fe1w0q-178"><strong>Note: </strong> Self-Service does not monitor the IdP metadata URL for changes. Changes to any of the SAML2 values or the certificate in the IdP will require the details to be updated in this tab.</p></blockquote><h3 data-block-id="mpvj22ox-6sydyk-188" id="unique-identifier-guid-attribute">Unique Identifier GUID Attribute</h3><p data-block-id="mpwh5t96-yl00l8-179">If you are <strong>not </strong>using the default attribute for the <strong>Unique Identifier GUID</strong> (see step 7), please update the <strong>Attribute Name</strong> field with the name of the attribute you will be using. To revert this field back to the default attribute name, click the <strong>Use Default</strong> button.</p><p data-block-id="mpwhizvk-l46v7v-021">Any changes on this tab only become active once <strong>Save Changes</strong> is clicked. To cancel any changes, click <strong>Discard Changes</strong>.</p><h3 data-block-id="mpvj22oy-jj845y-189" id="11-alter-sso-button-appearance-optional">11. Alter SSO button appearance (Optional)</h3><p data-block-id="mpwh5t96-yd7exy-180">Self-Service is able to provide both <strong>SP</strong>-Initiated or <strong>IdP</strong>-initiated logins. If <strong>SP</strong>-Initiated logins are to be used, there is the ability to customise the appearance of the <strong>SSO</strong> login button on the <strong>Self-Service</strong> login page.</p><p data-block-id="mpwhj7e2-ke6e8f-022">To make changes to the Log in with <strong>SSO</strong> button, go to the '<strong>3. Button Appearance</strong>'<strong> </strong>tab within<strong>SSO Settings.</strong></p><p data-block-id="mpwh7w2t-7619hz-207">It's possible to change the button text, foreground and background colours and the icon that appears on the button.</p><p data-block-id="mpwhl136-qm63os-023">All changes can be previewed on this page in the <strong>SSO Login Button Preview</strong> area. The default button appearance is currently shown in fig.5 below.</p><div class="image-view-figure"><figure data-block-id="mpwh8eyo-y2swhl-212" class="figure" dataalign="left" datadisplay="flex" style="width:940px;"><img data-block-id="mpwh889t-6h6z8q-211" src="https://cdn.document360.io/fc2cda72-4645-4b36-96bf-60439ec11f11/Images/Documentation/204001065318.png" class="adv-wysiwyg-img" mediatype="img" alt="" width="auto" height="auto" dataalign="left" datadisplay="flex" data-type="media-content" fixaspectratio="false" autoaspectratio="false" shadow="no" border="no" round="no" link="" newtab="" style="width:auto;height:auto;"><figcaption data-block-id="mpwh8eyo-xz6orm-213"><p data-block-id="mpwh8eyo-vvzrfl-214"><em>fig.5: SSO Settings - Button Appearance tab</em></p></figcaption></figure></div><p data-block-id="mpwh86sb-8dxdcl-208"><span type="spanMark" style="background:rgb(255, 255, 255);">Any changes on this tab only become active once <strong>Save Changes</strong> is clicked. To cancel any changes, click <strong>Discard Changes</strong>. </span></p><h3 data-block-id="mpvj22oy-a4mnm8-191" id="12-generate-add-guid-to-the-nominated-test-users-idp-profile"><span type="spanMark">12. Generate &amp; add GUID to the nominated test users IdP profile</span></h3><p data-block-id="mpwh5t97-veti2s-181">To prepare for an initial test, the nominated test user will need to be set up with a <strong>Unique Identifier GUID</strong> in the <strong>IdP</strong>.</p><p data-block-id="mpwha42w-od3hr1-001">See section 4.6 in the <a href="/iq/docs/sso-and-self-service-technical-factsheet" target="_self" rel="noopener noreferrer">SSO and Self Service - Technical Factsheet</a> for details on generating or obtaining <strong>GUID</strong>s.</p><p data-block-id="mpwha7mh-uxdoea-002">Once a new <strong>GUID</strong> is created/obtained, add it to the test user's <strong>IdP</strong> account profile. This should be set in the profile field where the attribute is configured to fetch it from (set in step 9).</p><h3 data-block-id="mpvj22oy-nrlsn5-192" id="13-provide-the-test-user-guid-to-cintra">13. Provide the test user GUID to Cintra</h3><p data-block-id="mpwh5t97-brvj25-182">Contact your Implementation Consultant or raise a support ticket and provide the following information in order for the test user to be created:</p><p data-block-id="mpwhrcwg-ylfriu-035">The test users <strong>full name</strong>, <strong>email address</strong> and <strong>the GUID</strong>.</p><h3 data-block-id="mpvj22oy-n8v64f-193" id="14-create-the-test-user-sso-account-in-selfservice-actioned-by-cintra">14. Create the test user SSO account in Self-Service - <span type="spanMark">Actioned By Cintra</span></h3><p data-block-id="mpwh5t97-y5pztc-183">Once the test user <strong>SSO</strong> account has been created <strong>Self-Service</strong>, <strong>Cintra</strong> will advise when this has been done.</p><h3 data-block-id="mpvj22oy-78qko7-194" id="15-test-user-login-attempt">15. Test user login attempt</h3><p data-block-id="mpwh5t97-51dstw-184">The nominated user can attempt the first <strong>SSO</strong> login. This can be done via an <strong>SP</strong>-initiated or <strong>IdP</strong>-initiated login process. The test user may or may not be asked to re-authenticate with their credentials, depending on <strong>IdP</strong> settings. Once they are past the authentication step they will be redirected to <strong>Self-Service</strong>.</p><p data-block-id="mpwhmcwl-upcuq4-024">If the <strong>SSO</strong> login attempt is successful, the user will see one of two pages:</p><ol data-block-id="mpvj22oy-kdza2l-195" start="1" style="--start:0;"><li data-block-id="mpvj22oy-25sytc-196"><p data-block-id="mpwh5t97-5yu0op-185">An date of birth verification page. This can be enabled for first login attempts for users to prove their identity before getting access to <strong>Self-Service</strong>.</p></li><li data-block-id="mpvj22oy-lhq55t-197"><p data-block-id="mpwh5t97-ott80k-186">The main <strong>Self-Service</strong> application. With additional verification steps disabled, the user will go straight into the <strong>Self-Service</strong> application.</p></li></ol><p data-block-id="mpwh5t98-8bs086-187">If the <strong>SSO</strong> login attempt is unsuccessful, the user will see a generic error page. <strong>Self-Service</strong> intentionally does not expose errors to the end user. The test user will not be able to provide any more details on the reason for the failure. If this is the case, please see the next step (Step 16 - Evaluate failed test login attempt(s) in the Testing Error Log.).</p><h3 data-block-id="mpvj22oy-ejm65s-198" id="16-evaluate-failed-test-login-attempts-in-the-testing-error-log">16. Evaluate failed test login attempt(s) in the Testing Error Log</h3><p data-block-id="mpwh5t98-523j25-188">Failed <strong>SSO</strong> Login attempts, and diagnostic information can be seen in the '<strong>4. Testing / Error Log</strong>'<strong> </strong>tab within <strong>SSO Settings.</strong></p><div class="image-view-figure"><figure data-block-id="mpwhaqzy-rtf6em-008" class="figure" dataalign="left" datadisplay="flex" style="width:651px;"><img data-block-id="mpvj22oy-s9gyux-199" src="https://cdn.document360.io/fc2cda72-4645-4b36-96bf-60439ec11f11/Images/Documentation/204001065319.png" class="adv-wysiwyg-img" mediatype="img" alt="" width="651" height="582" dataalign="left" datadisplay="flex" data-type="media-content" fixaspectratio="false" autoaspectratio="false" shadow="no" border="no" round="no" link="" newtab="" style="width:651px;"><figcaption data-block-id="mpwhaqzy-qub2io-009"><p data-block-id="mpwhaqzy-iw1img-010"><em>fig.6: SSO Settings - Testing / Error Log tab</em></p></figcaption></figure></div><p data-block-id="mpwh5t98-523j25-188">The entries in the log grid are ordered by most recent log in attempt first. The attribute and <strong>GUID</strong> information found in the <strong>SAML2</strong> response is shown and a message describing the reason for the failure.</p><p data-block-id="mpwhn6wc-bnbwev-026">With this information the most common reasons for authentication failures can be discovered. This mainly involves making sure the attribute and <strong>GUID</strong> values are as expected.</p><p data-block-id="mpwhnbto-snqtm5-028">The table below contains a list of the potential messages and further information:</p><div data-type="table-content"><table width="958" class="editor360-table fit-width" borderstyle="solid" style="max-width:958px;width:958px;"><colgroup><col style="width:479px;"><col style="width:479px;"></colgroup><tbody><tr><th colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpwh5t99-3b5qlb-189" style="text-align:center;">Message</p></th><th colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpwh5t99-43j46w-190" style="text-align:center;">Description</p></th></tr><tr><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpwh5t99-56roj1-191"><span type="spanMark"><strong>GUID is not present or in invalid format in SAML2 response</strong></span></p></td><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpwh5t99-8iidth-192"><span type="spanMark">The User Identifier GUID attribute value is empty or it is not correctly formatted as a GUID (or a base64 encoded GUID). The value that was found is shown in the 'Saml2 Response Guid / Attribute' column </span></p><p data-block-id="mpwhnm27-a7u4wg-030"><span type="spanMark"><strong>Impact </strong>( Impact only relates to SSO authentication. Any users using standard username/password and AD logins will not be affected by any failing SSO authentication. )Critical to the user. Other user GUID values may/may not be in the correct format.</span></p><p data-block-id="mpwhb74l-61zlkh-012"><span type="spanMark"><strong>Customer Resolution</strong></span></p><p data-block-id="mpwhnpjr-t9pv1f-031"><span type="spanMark">Check the User Identifier GUID is being fetched from the IdP users profile and make sure it's in the correct format. See Section 4.6 in the </span><a href="/iq/docs/sso-and-self-service-technical-factsheet" target="_self" translate="no" rel="noopener"><span type="spanMark">SSO and Self Service - Technical Factsheet</span></a></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpwh5t9a-koqwwy-193"><span type="spanMark"><strong>No SAML2 settings configured in this Self Service</strong></span></p></td><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpvj22oz-t2bk4e-200"><span type="spanMark">SSO is not enabled or configuration data has been removed from this Self Service instance</span></p><p data-block-id="mpvj22oz-ro2zgb-201"><span type="spanMark"><strong>Impact </strong>( Impact only relates to SSO authentication. Any users using standard username/password and AD logins will not be affected by any failing SSO authentication. )</span></p><p data-block-id="mpvj22oz-qyk4xi-202"><span type="spanMark">Critical. No SSO logins will be possible.</span></p><p data-block-id="mpvj22oz-wohyxs-203"><span type="spanMark"><strong>Customer Resolution</strong></span></p><p data-block-id="mpvj22oz-bqmxre-204"><span type="spanMark">Attempt to re-enable SSO and set up configuration in Self-Service - steps 6-10.</span></p></td></tr><tr><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpwh5t9b-21wivs-194"><span type="spanMark"><strong>Attribute name not found for this application (ID:1)</strong></span></p></td><td colspan="1" rowspan="1" colwidth="479"><p data-block-id="mpwh5t9b-qlbywt-195"><span type="spanMark">The expected User Identifier GUID attribute name can't be found in the SAML2 response.</span></p><p data-block-id="mpwhbn36-n7bofu-013"><span type="spanMark"><strong>Impact*</strong></span></p><p data-block-id="mpwhogs2-vt15j5-032"><span type="spanMark">Critical. No SSO logins will be possible.</span></p><p data-block-id="mpwhbpyu-ad7c1g-014"><span type="spanMark"><strong>Customer Resolution</strong></span></p><p data-block-id="mpwhngv9-9seb5p-029"><span type="spanMark">Check the Attribute Name specified in Self-Service (step 10) matches the attribute name setup on the IdP application (step 9)</span></p></td></tr></tbody></table></div><p data-block-id="mpwh5t9b-adqu34-196">Please raise a <strong>Support</strong> request if the authentication fails and the suggested resolutions fail to resolve the problem.</p><h3 data-block-id="mpvj22p0-6xetqm-205" id="17-generatelink-all-remaining-user-guid-to-idp-user-profiles-in-the-idp">17. Generate/Link all remaining user GUID to IdP user profiles in the IdP</h3><p data-block-id="mpwh5t9b-ectmqh-197">Once a successful authentication is achieved (step <strong>16</strong>) this gives assurance that the <strong>SAML2</strong> configuration is correct in <strong>Self-Service</strong> and at the <strong>IdP</strong>.</p><p data-block-id="mpwhomjd-2fxkg4-033">All users that are required to have <strong>Self-Service SSO</strong> authentication should be set up in a similar way to the test user in step <strong>12</strong>.</p><p data-block-id="mpwhoqzl-dawa6a-034">You may not want all your users to have <strong>SSO</strong> logins, in that situation please advise your <strong>Implementation Consultant</strong> which of your users you require traditional (username/password) logins.</p></body></html>
