Setting Up Single Sign-On

Support Note
This topic is not relevant to all Bluescape users and may not apply to all Organizations. If you’re unsure whether your Organization has this capability, please reach out to your IT department.

Single Sign-On (SSO) allows you to sign in to Bluescape from a centralized identity provider (IDP), simplifying both user experience and user management. Bluescape supports SSO through IDPs using the SAML 2.0 standard.
The certified SAML IDPs for Bluescape are:

  • Okta
  • Azure Active Directory
  • Ping Federate
  • F5

Setting up SSO involves an exchange of information between the customer and Bluescape Support. To set up SSO in Bluescape:

  1. Contact Bluescape Support and inform them that you want to set up SSO for your organization with one of the IDPs listed above.

  2. Provide Support with the contact email address of your SSO administrator.

  3. Support then provides you with the following URLs:


    Note: These URLS contain placeholders for the <customer_saml_provider_name>, <acs_id>, <saml_id>, and <identity_provider_name> because they have not been generated yet.

  4. Map the Attribute Statements as follows:


    ** Whatever value you choose for the user_guid attribute must be unique for each user and unchangeable, even if the user’s email changes. Typical values include user.id for Okta, user.objectid for AzureAD, and ObjectGUID for ADFS.

  5. Provide Bluescape Support with the URL to the metadata XML file created by your SSO provider.

  6. Support uses this metadata URL to set up a test organization and provide you with the following (updated) URLs:

  • Entity ID
  • ACS URL
  • Single Logout Endpoint
  • SSO URL
  1. Use the above information to complete your IDP configuration.

  2. Have a user log in to the test organization using the SSO URL provided by Support.

  3. If the login is successful, provide Bluescape Support with permission to apply the SSO setup to the actual organization.

  4. All users can now log in via their SSO provider or the SSO URL.

Note: Okta includes a preconfigured Bluescape enterprise application in their Applications list. You should not use it as it is not configured correctly for the current release.

Haven’t found the answer? Ask the community for help. Not what you were looking for? Search the community.