> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Single Sign-On with OneLogin (SAML)

> Configure SAML-based SSO between OneLogin and Iru Endpoint. Create the SAML application in OneLogin and map user attributes for admin authentication.

### About OneLogin SAML Integration

Single Sign-On with OneLogin (SAML) in Iru Endpoint lets you set up SAML-based SSO integration with OneLogin for users accessing Iru Endpoint through their OneLogin credentials.

#### How It Works

OneLogin SAML integration lets users authenticate to Iru Endpoint using their existing OneLogin credentials. Once configured, users can access Iru Endpoint through a single sign-on experience.

The integration works by establishing a trusted relationship between Iru Endpoint and OneLogin, where OneLogin acts as the identity provider (IdP) and Iru Endpoint acts as the service provider (SP). When users attempt to access Iru Endpoint, they're redirected to OneLogin for authentication, and upon successful login, OneLogin sends a SAML assertion back to Iru Endpoint confirming the user's identity. SSO can be used for [Iru Endpoint Web App](/en/endpoint/getting-started/foundation/admins-and-access) sign-in and for [Require Authentication with Automated Device Enrollment](/en/endpoint/enrollment/configure-require-authentication-for-enrollment).

<Tabs>
  <Tab title="Iru Web App Configuration">
    ### Setting Up the SAML Connection

    <Note>
      You'll need to complete the initial setup in Iru Endpoint first to get the configuration information required for OneLogin. After copying the Entity ID and ACS URL, switch to the [**OneLogin Configuration**](#onelogin-configuration) tab and continue with [**Configuring OneLogin Application**](#configuring-onelogin-application).
    </Note>

    <Steps>
      <Step title="Navigate to the Account Menu Button">
        In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu).
      </Step>

      <Step title="Access Authentication Settings">
        Click the **Access** option in the menu.

        <Frame>
          <img src="https://mintcdn.com/iru/8BYPjuKZa-zyEEf_/assets/media/images/iru-nav-access.png?fit=max&auto=format&n=8BYPjuKZa-zyEEf_&q=85&s=466fdf5fb47efd6bab8b450a5a1e8302" alt="Screenshot of the account menu with Access option highlighted" width="562" height="1040" data-path="assets/media/images/iru-nav-access.png" />
        </Frame>
      </Step>

      <Step title="Select Admin and Authentication">
        Select the **Admin and authentication** tab (selected by default) and scroll down to **Authentication methods**.
      </Step>

      <Step title="Add Authentication Method">
        Click **+ Authentication method**.
      </Step>

      <Step title="Enter Display Name">
        Enter a display name for the SSO Connection.
      </Step>

      <Step title="Select Authentication Method">
        Select **SAML** for the Authentication method.
      </Step>

      <Step title="Create Connection">
        Click **Create**.
      </Step>

      <Step title="Configuration Information">
        Click **Configuration information** if that section is not already expanded.
      </Step>

      <Step title="Copy Service Provider Entity ID">
        Copy the **Service provider entity ID** into a text document for later use. You'll need this for the OneLogin configuration.
      </Step>

      <Step title="Copy ACS URL">
        Copy the **Assertion consumer service (ACS) URL** into a text document for later use. You'll need this for the OneLogin configuration.

        <Frame>
          <img src="https://mintcdn.com/iru/Qq59wQ8jCPy0XJe9/assets/media/images/iru-support-google-saml_11-08-26.png?fit=max&auto=format&n=Qq59wQ8jCPy0XJe9&q=85&s=7d56d5b22f71fb05dd59c83555c02430" alt="Configuration Information, Service provider entity ID, and Assertion consumer service (ACS) URL" width="2166" height="940" data-path="assets/media/images/iru-support-google-saml_11-08-26.png" />
        </Frame>
      </Step>

      <Step title="Keep Tab Open">
        Keep the Iru Endpoint configuration modal open, then switch to the [**OneLogin Configuration**](#onelogin-configuration) tab to continue with [**Configuring OneLogin Application**](#configuring-onelogin-application).
      </Step>
    </Steps>

    ### Configuring Iru Endpoint SAML Connection

    <Note>
      After completing the OneLogin configuration, return here to finish [**Configuring Iru Endpoint SAML Connection**](#configuring-iru-endpoint-saml-connection) in Iru Endpoint. You'll need the Single Sign-on URL, IdP Entity ID, and certificate from OneLogin.
    </Note>

    <Steps>
      <Step title="Return to Iru Endpoint">
        Go back to the Custom SAML modal in Iru Endpoint.
      </Step>

      <Step title="Set IdP Attribute">
        Set **IdP attribute** to **Subject**.
      </Step>

      <Step title="Set Attribute Name">
        Leave **Attribute name** blank.
      </Step>

      <Step title="Set User Attribute">
        Set **User attribute** to **User Principal Name (UPN)**.
      </Step>

      <Step title="Add IdP Entity ID">
        Paste the **Issuer URL** you copied from OneLogin into the **IdP Entity ID** field.
      </Step>

      <Step title="Configure Sign In URL">
        Paste the **SAML 2.0 Endpoint (HTTP)** URL you copied from OneLogin into the **IdP Single Sign-on URL** field.
      </Step>

      <Step title="Upload Certificate">
        Upload the OneLogin certificate you downloaded earlier.

        <Frame>
          <img src="https://mintcdn.com/iru/rklQKFJvStbahPGs/assets/media/images/onelogin-saml_15-50-39.png?fit=max&auto=format&n=rklQKFJvStbahPGs&q=85&s=8448c85032eb37ca87f0580c582046c0" alt="Iru Endpoint upload OneLogin certificate" width="1336" height="620" data-path="assets/media/images/onelogin-saml_15-50-39.png" />
        </Frame>
      </Step>

      <Step title="Set Protocol Binding">
        Set the **Protocol Binding** to **HTTP-POST**.
      </Step>

      <Step title="Set Request Algorithm">
        Ensure that the **Request Algorithm** is set to **RSA-SHA256**.
      </Step>

      <Step title="Set Digest Algorithm">
        Ensure that **Sign Request Algorithm Digest** is set to **SHA256**.
      </Step>

      <Step title="Enable Sign Request">
        Ensure that **Sign Request** is enabled.
      </Step>

      <Step title="Set Response Signature Verification">
        Set the **Response Signature Verification** to **Assertion**.
      </Step>

      <Step title="Set Destination">
        Leave the **Destination** field blank.
      </Step>

      <Step title="Set Allowed Signature Algorithm">
        Set **Allowed Signature Algorithm** to **RSA-SHA256**.
      </Step>

      <Step title="Set Allowed Digest Algorithm">
        Set **Allowed Digest Algorithm** to **SHA256**.
      </Step>

      <Step title="Save Configuration">
        Click **Save**.

        <Frame>
          <img src="https://mintcdn.com/iru/rklQKFJvStbahPGs/assets/media/images/onelogin-saml_6-04-14.png?fit=max&auto=format&n=rklQKFJvStbahPGs&q=85&s=0c9a311a61ea63a12ffd53e6c6e5a165" alt="Iru Endpoint Save for SAML configuration" width="1336" height="724" data-path="assets/media/images/onelogin-saml_6-04-14.png" />
        </Frame>
      </Step>
    </Steps>

    ### Allow for Tenant Authentication

    Once you have configured the SAML connection in Iru Endpoint and your identity provider, you can allow its use for tenant authentication. For step-by-step instructions, please refer to the **Allowing Tenant Authentication and Managing Connections** section in our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on).

    ### Limit Authentication to Domain

    When configuring the SAML connection, you can optionally limit authentication to one or more domains. This can be useful when the SSO connection could authenticate to multiple domains. You can limit the authentication to your Iru tenant to a subset of the available domains.

    ### Enforcing Single Sign-On

    Once you have configured at least one Single Sign-on connection, you can disable Passkey, Google Social, and Microsoft Social connections. Disabling these connections will disable the ability for Iru Endpoint administrators in your tenant to authenticate via those methods. Please refer to our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on) for step-by-step instructions.

    ### Testing the Integration

    <Steps>
      <Step title="Add Test User">
        Add a test user to the **Admin Team** in Iru Endpoint by clicking **New User**.
      </Step>

      <Step title="Configure User Information">
        Fill in all of the corresponding user information. This user must exist in OneLogin and must be assigned to the Iru Endpoint SSO app in your OneLogin tenant.
      </Step>

      <Step title="Submit User">
        Click **Submit**.
      </Step>

      <Step title="Close Invite Window">
        Once the invite is submitted, close the Invite User window.
      </Step>

      <Step title="Refresh Access Page">
        Refresh the Access page in Iru Endpoint. You should see the user you added.
      </Step>

      <Step title="Test SSO Login">
        Go to the user's email to accept the invite and log in with the new SAML SSO connection.
      </Step>
    </Steps>
  </Tab>

  <Tab title="OneLogin Configuration">
    <Note>
      Before starting the OneLogin configuration, complete [**Setting Up the SAML Connection**](#setting-up-the-saml-connection) in the [**Iru Web App Configuration**](#iru-web-app-configuration) tab to get the Service Provider Entity ID and ACS URL. You'll need these values to configure the OneLogin application.
    </Note>

    ### Configuring OneLogin Application

    <Steps>
      <Step title="Create New Application">
        In OneLogin, create a new app using the **Add SAML Custom Connector (Advanced)** app. Navigate to:

        ```
        https://{YourSubdomain}.onelogin.com/apps/new/110016
        ```
      </Step>

      <Step title="Set Name">
        Set the **name**.
      </Step>

      <Step title="Set Portal Visibility">
        Set whether the app should be visible in the portal.
      </Step>

      <Step title="Set Icons">
        Set the **icons** for the app.
      </Step>

      <Step title="Set Description">
        Set the **Description**.
      </Step>

      <Step title="Click Save">
        Click **Save**.

        <Frame>
          <img src="https://mintcdn.com/iru/rklQKFJvStbahPGs/assets/media/images/onelogin-saml_15-18-35.png?fit=max&auto=format&n=rklQKFJvStbahPGs&q=85&s=504786fc7a868ad8db4554879821eba2" alt="OneLogin app name portal visibility icons description Save" width="2412" height="1848" data-path="assets/media/images/onelogin-saml_15-18-35.png" />
        </Frame>
      </Step>

      <Step title="Open Configuration Tab">
        Click the **Configuration** tab.
      </Step>

      <Step title="Configure Entity ID">
        Paste the **Iru Entity ID** (Service provider entity ID) into the **Audience (EntityID)** field.
      </Step>

      <Step title="Configure ACS URL">
        Paste the **Iru ACS URL** (Assertion consumer service URL) into the **Recipient**, **ACS (Consumer) URL Validator**, and **ACS (Consumer) URL** fields.

        <Frame>
          <img src="https://mintcdn.com/iru/rklQKFJvStbahPGs/assets/media/images/onelogin-saml_15-24-05.png?fit=max&auto=format&n=rklQKFJvStbahPGs&q=85&s=f8053e77ebc64aa33ad16a1c040bf487" alt="OneLogin Configuration Audience Entity ID Recipient ACS URL" width="2112" height="1544" data-path="assets/media/images/onelogin-saml_15-24-05.png" />
        </Frame>
      </Step>

      <Step title="Configure SAML Initiator">
        Set the **SAML initiator** to **OneLogin**.
      </Step>

      <Step title="Set Name ID Format">
        Set the **SAML nameID format** to **Email**.
      </Step>

      <Step title="Set Issuer Type">
        Set the **SAML issuer type** to **Generic**.
      </Step>

      <Step title="Set Signature Element">
        Set the **SAML signature element** to **Assertion**.

        <Frame>
          <img src="https://mintcdn.com/iru/RojwfOtw4zjvTAlh/assets/media/images/onelogin-saml_15-28-40.png?fit=max&auto=format&n=RojwfOtw4zjvTAlh&q=85&s=812f19ce26ece8473f0704cf03a9d640" alt="OneLogin SAML initiator nameID format issuer signature Assertion" width="2000" height="1102" data-path="assets/media/images/onelogin-saml_15-28-40.png" />
        </Frame>
      </Step>

      <Step title="Configure Parameters">
        Click the **Parameters** tab.
      </Step>

      <Step title="Name ID">
        Ensure that the **Name ID** value is set to **Email**.

        <Frame>
          <img src="https://mintcdn.com/iru/rklQKFJvStbahPGs/assets/media/images/onelogin-saml_15-31-07.png?fit=max&auto=format&n=rklQKFJvStbahPGs&q=85&s=3dcb042ba602fa2a40dc6dff316b93ea" alt="OneLogin Parameters Name ID set to Email" width="2120" height="1114" data-path="assets/media/images/onelogin-saml_15-31-07.png" />
        </Frame>
      </Step>

      <Step title="Configure SSO Settings">
        Click the **SSO** tab.
      </Step>

      <Step title="Set SAML Signature Algorithm">
        Set the **SAML Signature Algorithm** to **SHA-256**.
      </Step>

      <Step title="Copy Issuer URL">
        Copy the **Issuer URL** and save it. You will paste this into the **IdP Entity ID** field in Iru Endpoint.
      </Step>

      <Step title="Copy SAML Endpoint URL">
        Copy the **SAML 2.0 Endpoint (HTTP)** URL and save it. You will use this for the **IdP Single Sign-on URL** in the Iru configuration.
      </Step>

      <Step title="Click Save">
        Click **Save**.

        <Frame>
          <img src="https://mintcdn.com/iru/rklQKFJvStbahPGs/assets/media/images/onelogin-saml_15-34-47.png?fit=max&auto=format&n=rklQKFJvStbahPGs&q=85&s=0625d1a0ae5f769aad2ff9a32afd4872" alt="OneLogin SSO tab Issuer URL SAML 2.0 Endpoint Save" width="2294" height="1480" data-path="assets/media/images/onelogin-saml_15-34-47.png" />
        </Frame>
      </Step>

      <Step title="SSO Tab">
        Click the **SSO** tab.
      </Step>

      <Step title="View Certification">
        Click **View Details**.

        <Frame>
          <img src="https://mintcdn.com/iru/rklQKFJvStbahPGs/assets/media/images/onelogin-saml_15-46-02.png?fit=max&auto=format&n=rklQKFJvStbahPGs&q=85&s=e1ab542c0df31d0ec81dfd6ed696dfd0" alt="OneLogin SSO tab View Details for certificate" width="2242" height="1240" data-path="assets/media/images/onelogin-saml_15-46-02.png" />
        </Frame>
      </Step>

      <Step title="Download Certificate">
        Click **Download**.

        <Frame>
          <img src="https://mintcdn.com/iru/rklQKFJvStbahPGs/assets/media/images/onelogin-saml_15-42-34.png?fit=max&auto=format&n=rklQKFJvStbahPGs&q=85&s=86eb1bc3bc6942e76acb4c74ab352317" alt="OneLogin Download certificate" width="2056" height="2024" data-path="assets/media/images/onelogin-saml_15-42-34.png" />
        </Frame>
      </Step>
    </Steps>

    <Note>
      After completing the OneLogin Configuration, return to the **Iru Web App Configuration** tab to finish setting up the SAML connection using the SSO URL, Entity ID, and certificate you copied from OneLogin.
    </Note>
  </Tab>
</Tabs>
