Manage Single Sign-On (SSO)
This feature requires entitlement. To enable this feature, contact your Account Manager. Once the entitlement has been granted, follow the steps below.
Enable SSO
-
Log in to your Atlas↗ account.
-
Click the profile icon in the upper-right corner, then click on the Account Settings dropdown.
-
Select SSO from the list.
-
Click on Configure SSO to open the SSO set up page in a new tab.
-
At the lower-right of the SSO set up page, click Get Started.
-
Select Single Sign-On.
-
Select your identity provider, then click Next to continue.
NOTE: The steps may vary depending on the identity provider selected. In this example, Okta is selected.
-
Complete the steps specific to your chosen identity provider.
-
Create an application in your identity provider, then click Next.
-
Enter the required URLs to configure connection, then click Create Connection.
-
Click on Proceed to acknowledge connection.
-
Proceed in testing the connection.
-
-
Once done with creating connection, the domain verification will be activated. Click Domain Configuration to proceed.
-
Enter your domain, then click Add Domain.
-
Verify your domain using DNS TXT record.
-
Copy the TXT Record Name and TXT Record Content codes.
-
Go to your DNS provider and add a TXT type DNS record.
NOTE: The user interface may be different depending on the DNS provider. -
Paste the copied codes into the corresponding fields, then save the record.
-
After saving the record, return to the Atlas Domain Configuration page and click Verify.
-
Once verified, click Done.
-
-
Click Enable Connection.
-
Click Proceed.
-
You have successfully enabled the SSO connection.
Add User
In your identity provider, add the user's email address. After the user is successfully added, the identity provider logo will be displayed on the Provider tab of the User window.
NOTE: New SSO users are assigned the selected role upon joining the platform. Users without an assigned role may see a message directing them to contact a system administrator for role assignment.
Log In
After the connection is established and the user has been added, follow the steps below to sign in.
-
Log in to your Atlas↗ account, then click Continue to proceed to identity provider authentication.
-
Click Next. NOTE: In this example, Okta is used to log in.
-
Select the security method.
-
Enter the authentication code, then click Verify.
-
Enter your password, then click Verify.
-
You have successfully logged in.
NOTE: New SSO users are assigned the selected role upon joining the platform. Users without an assigned role may see a message directing them to contact an administrator for role assignment. To assign a role, see Assign User Role below.
By default, users configured for SSO are redirected to their identity provider when signing in with their organization email address. The Break Glass Login feature provides an alternative sign-in method for users who are unable to access their account through Single Sign-On (SSO) or who need to sign in using their native Atlas credentials.
Use cases include:
- Recovering access after an SSO configuration issue.
- Signing in with a native Atlas account instead of SSO credentials.
- Accessing the platform when the identity provider is unavailable.
To use the Break Glass log in, go to this link: https://atlas.globalsign.com/breakglass
Assign User Role
- Go to your active SSO connection.
-
At the bottom of the connection, select the appropriate role for the user, then click Save Roles.
- You have now selected a role for the user.
Delete SSO
WARNING: Deleting the SSO connection will remove all users associated to it. This cannot be undone.
- Go to your active SSO connection.
- At the bottom of the connection, click Delete SSO.
-
Click Delete on pop-up page to acknowledge that all associated users will be removed in once deleted.