On this page

Manage Single Sign-On (SSO)

This feature requires entitlement. To enable this feature, contact your Account Manager. Once the entitlement has been granted, follow the steps below. 

Enable SSO

  1. Log in to your Atlas↗ account.  

  2. Click the profile icon in the upper-right corner, then click on the Account Settings dropdown.

    atlas-sso-article1.png

  3. Select SSO from the list.

    atlas-sso-article2.png

  4. Click on Configure SSO to open the SSO set up page in a new tab.

    atlas-sso-article3.png

  5. At the lower-right of the SSO set up page, click Get Started

    atlas-sso-article4.png

  6. Select Single Sign-On

    atlas-sso-article5.png

  7. Select your identity provider, then click Next to continue. 

    NOTE: The steps may vary depending on the identity provider selected. In this example, Okta is selected.

    atlas-sso-article26.png

  8. Complete the steps specific to your chosen identity provider.

    1. Create an application in your identity provider, then click Next

      atlas-sso-article8.png

    2. Enter the required URLs to configure connection, then click Create Connection.

      atlas-sso-article9.png

    3. Click on Proceed to acknowledge connection. 

      atlas-sso-article10.png

    4. Proceed in testing the connection.

  9. Once done with creating connection, the domain verification will be activated. Click Domain Configuration to proceed. 

    atlas-sso-article11.png

  10.  Enter your domain, then click Add Domain

    atlas-sso-article12.png

  11.  Verify your domain using DNS TXT record.

    1. Copy the TXT Record Name and TXT Record Content codes. 

      atlas-sso-article13.png

    2. Go to your DNS provider and add a TXT type DNS record.

      NOTE: The user interface may be different depending on the DNS provider.

    3. Paste the copied codes into the corresponding fields, then save the record. 

    4. After saving the record, return to the Atlas Domain Configuration page and click Verify.

      atlas-sso-article14.png
       

    5. Once verified, click Done

      atlas-sso-article15.png

  12.  Click Enable Connection. 

    atlas-sso-article16.png

  13.  Click Proceed

    atlas-sso-article17.png

  14.  You have successfully enabled the SSO connection. 

    atlas-sso-article18.png

Add User

In your identity provider, add the user's email address. After the user is successfully added, the identity provider logo will be displayed on the Provider tab of the User window.

NOTE: New SSO users are assigned the selected role upon joining the platform. Users without an assigned role may see a message directing them to contact a system administrator for role assignment.

atlas-sso-article21.png

Log In

After the connection is established and the user has been added, follow the steps below to sign in.

  1. Log in to your Atlas↗ account,  then click Continue to proceed to identity provider authentication.

    atlas-sso-article30.png

  2. Click Next. NOTE: In this example, Okta is used to log in. 

    atlas-sso-article29.png

  3. Select the security method. 

    atlas-sso-article31.png

  4. Enter the authentication code, then click Verify.

    atlas-sso-article32.png

  5. Enter your password, then click Verify.

    atlas-sso-article33.png

  6. You have successfully logged in. 

NOTE: New SSO users are assigned the selected role upon joining the platform. Users without an assigned role may see a message directing them to contact an administrator for role assignment. To assign a role, see Assign User Role below. 

atlas-sso-article22.png

By default, users configured for SSO are redirected to their identity provider when signing in with their organization email address. The Break Glass Login feature provides an alternative sign-in method for users who are unable to access their account through Single Sign-On (SSO) or who need to sign in using their native Atlas credentials.

Use cases include:

  • Recovering access after an SSO configuration issue.
  • Signing in with a native Atlas account instead of SSO credentials.
  • Accessing the platform when the identity provider is unavailable.

To use the Break Glass log in, go to this link: https://atlas.globalsign.com/breakglass

Assign User Role

  1. Go to your active SSO connection. 
  2. At the bottom of the connection, select the appropriate role for the user, then click Save Roles.


    atlas-sso-article19.png
  3. You have now selected a role for the user.

    atlas-sso-article20.png

Delete SSO 

WARNING: Deleting the SSO connection will remove all users associated to it. This cannot be undone.

  1. Go to your active SSO connection.
  2. At the bottom of the connection, click Delete SSO.

    atlas-sso-article27.png
  3. Click Delete on pop-up page to acknowledge that all associated users will be removed in once deleted.

    atlas-sso-article28.png