Skip to main content

Setting up SAML SSO for external services in Oneteam

In this article, we explain how to set up SAML Single Sign-On for an external service, so your employees can use their Oneteam account to log in automatically.

Written by Sanne Lodders

With SAML Single Sign-On (SSO), Oneteam acts as the Identity Provider (IdP). This means your employees can use the account they already have in Oneteam to access supported external services without creating or remembering a separate password.

Once SSO is configured, you can add the external service as a shortcut in Oneteam. When an employee clicks the shortcut, Oneteam authenticates them and automatically signs them in to the external service.

What you need

Before you start, make sure you have:

  • Admin access in Oneteam

  • Admin access to the external service you want to connect

  • SAML configuration details from the external service

The external service is the Service Provider (SP), while Oneteam is the Identity Provider (IdP).

Step 1: Configure the external service

First, configure the external service to use Oneteam as its SAML Identity Provider. In the admin environment of the external service:

  1. Go to the SAML or Single Sign-On settings.

  2. Choose SAML as the authentication method.

  3. Enter the SAML details for Oneteam when requested.

  4. Save the SAML configuration.

The external service may ask for information such as:

  • IdP Entity ID

  • IdP metadata URL

  • SSO URL

  • X.509 signing certificate

  • Other SAML attributes or claims

Use the Oneteam SAML details provided for your organisation when configuring the external service. Most of these attributes can be found on our metadata URL: https://login.oneteam.io/api/saml/idp/metadata

Important: the exact fields and names depend on the external service. If it asks for an IdP metadata URL or XML file, use the Oneteam metadata information provided for your SAML connection.

Step 2: Add the external service as a shortcut in Oneteam

Once the external service has been configured to use Oneteam as its Identity Provider, add it to Oneteam.

  1. In Oneteam, go to Settings > Apps&Shortcuts.

  2. Click '+ Add shortcut'.

  3. Choose 'Add external link'.

  4. Under 'Type', select SAML.

  5. Enter the SAML details for the external service.

You may need to fill in the following fields:

  • Shortcut link: the link employees use to access the external service from Oneteam.

  • SP Entity ID or metadata URL: the unique identifier or metadata URL of the external service.

  • ACS URL: the URL where the external service receives the SAML response from Oneteam.

  • SP login URL: the URL where the SAML login process starts for the external service.

  • SP logout URL: the URL employees are sent to after logging out of the external service.

Click 'Save' once all required fields have been completed.

Step 3: Employees use their Oneteam account

Once the shortcut has been configured, employees can access the external service directly from Oneteam.

When an employee clicks the shortcut:

  1. Oneteam identifies the employee using their existing Oneteam account.

  2. Oneteam sends the required SAML authentication response to the external service.

  3. The external service verifies the response.

  4. The employee is automatically logged in.

This means employees do not need to enter a separate username or password for the external service.

Step 4: Match user email addresses

The external service must be able to identify the employee from the information provided by Oneteam. In most cases, this is based on the employee's email address.

Make sure the email address configured for the employee in the external service matches the email address used in Oneteam. If an employee has an old email address or alias in the external service, update it so that it matches their Oneteam account.

Step 5: Test the connection

Before making the shortcut available to everyone, test the connection with one employee account.

  1. Add the shortcut in Oneteam.

  2. Open the shortcut using the test employee's Oneteam account.

  3. Check that the external service logs the employee in automatically.

  4. Confirm that the employee is given the correct access and permissions.

If the test is successful, you can make the shortcut available to the rest of your organisation.

Login not working?

If an employee cannot log in automatically, check the following:

  • The employee exists in both Oneteam and the external service.

  • The email address or other user identifier matches between the two systems.

  • The external service is configured to use Oneteam as the Identity Provider.

  • The SAML Entity ID, SSO URL, certificate and other SAML settings have been copied correctly.

  • The employee has permission to access the external service.

  • The ACS URL and other Service Provider details are correct.

  • The SAML configuration has been saved and activated in the external service.

Still unable to complete the setup? Contact Oneteam Support and include the name of the external service, the SAML configuration you are using, and a screenshot or error message from the failed login attempt. With that information, we can help investigate the issue.

Feel free to reach out on the live chat if we can advise or help you with anything. 👉

Did this answer your question?