Configure Single Sign-On (SSO)

Prev Next

Introduction

SAFE supports Single Sign-On (SSO) to enable secure, centralized authentication and seamless access for enterprise users. By integrating SAFE with your organization’s identity provider (IDP), users can authenticate using their existing corporate credentials, improving security, reducing password fatigue, and simplifying user access management.

SAFE supports industry-standard SAML 2.0–based SSO and provides configuration guidance for commonly used identity providers, along with generic setup parameters and troubleshooting steps.

Supported SSO

Use the links below to configure or troubleshoot SSO for your identity provider:

Generic SSO Parameters

Overview of SAML 2.0 parameters required to integrate SAFE with any compatible identity provider.

Link: Generic SSO Parameters

Microsoft Entra ID (Azure AD) SSO

Step-by-step instructions to configure SAFE SSO using Microsoft Entra ID (formerly Azure Active Directory).

Link: Microsoft Entra ID (Azure AD) SSO

Active Directory Federation Services (AD FS) SSO

Guidance for integrating SAFE with on-premises AD FS using SAML 2.0.

Link: Active Directory Federation Services (AD FS)

Okta SSO

Instructions to configure SAFE as a SAML application in Okta for user authentication.

Link: Okta SSO

Duo SSO

Steps to integrate SAFE with Duo Single Sign-On for secure access with MFA enforcement.

Link: Configure SSO with Duo

OneLogin SSO

Configuration guide for enabling SAFE SSO using OneLogin as the identity provider.

Link: OneLogin SSO

Troubleshooting

Refer to the troubleshooting section, which includes common SSO issues, error scenarios, and recommended steps to diagnose and resolve authentication failures.

Link: Troubleshooting Guide