Skip to main content

Enabling SAML single sign-on for your organization

Enable SSO for your Organization

Written by Zachary Allen
Updated this week

Mindsmith allows you to sign in through your organization's Identity Provider using SAML SSO.

Note: SSO requires the Enterprise tier of Mindsmith. Please contact us if you'd like to enable it for your organization.

Also note: Identity Provider Initiated authentication is not currently supported. User provisioning is manual. Users may sign in using the SSO provider, but they must be invited to your workspace and assigned a license to be a part of the organization.

Setting up your Identity Provider

You will typically begin by setting up a new application inside of your Identity Provider. Once your application is created, download the Metadata XML provided by your system.

You can find the required Mindsmith service provider information here.

Configuring SSO in Mindsmith

To configure SSO, you must be an admin of an Enterprise-tier organization.

  1. Navigate to your organization settings and click on the Security tab.

Screenshot

  1. Click the Add SAML Provider button.

  2. Paste the SAML Metadata XML from your Identity Provider into the text area.

  3. Click Save Configuration.

Screenshot

Adding Authorized Domains

Once your provider is saved, you need to add the email domains you would like to associate with it. Only users with email addresses matching these provided domains will be able to sign in using Single Sign-On.

  1. Under the Authorized Domains section, click Add Domain.

  2. Type in your organization's domain (for example, example.com).

  3. Click Add Domain to save.

Screenshot

Tip: If you ever need to update your SAML Metadata XML, click Edit next to your provider details. You can also permanently delete a provider or an authorized domain by clicking the red trash can icon next to them.

Finalizing your setup

The remainder of the process takes place inside of your Identity Provider. Make sure to establish the proper access controls for your organization's users so they can successfully authenticate.

Mindsmith uses BoxyHQ to securely manage SAML SSO connections. For attribute mapping information and vendor-specific setup guides, you can visit this documentation.

Did this answer your question?