Set up Enterprise single sign-on
Improve security, user experience, and user administration for your organization
읽는 시간 5분최근 업데이트: 11일 전
Implement Enterprise single sign-on (SSO) for these purposes:
- Simplify the login process. To access Unity products and services, users sign in with their company's credentials instead of a Unity ID and password.
- Reduce the risk of lost or stolen passwords through a single authentication point.
- Improve the administration workflow through user provisioning on the first user sign-in.
SSO is available only with these Unity plans:
- Unity Enterprise
- Unity Industry plan
Prerequisites
Before you can set up SSO for your organization, ensure that you meet these prerequisites:
-
You must have the Owner or Manager user type within your organization. Read more about user types, roles, and permissions.
-
You must have at least one validated domain. You can't enable Enterprise SSO for an organization that has no validated domain.
-
You must have created a SAML 2.0 application in your Identity Provider (IdP) service.Unity SSO uses the Security Assertion Markup Language (SAML) 2.0 protocol. This protocol enables secure communication between the IdP and Unity.Unity SSO supports the following IdPs:
Configure Enterprise SSO
Configuring Enterprise SSO exchanges metadata in both directions: Unity's settings go to your IdP, and your IdP's settings come back to Unity.
Both sets of settings are on the Single Sign-on tab of the SSO & SCIM page, under step 1, Configure Enterprise Single Sign-on:
- The Unity card holds the settings to submit to your IdP.
- The Identity Provider card holds the settings that your IdP supplies.
Submit the Unity settings to your IdP
To submit the Unity settings to your IdP, follow these steps:
-
Go to your organization's IdP portal and create a SAML 2.0 application.
-
In the Unity Dashboard, open the Account menu and select Manage organization.
-
In the Administration menu, select SSO & SCIM.
-
On the Single Sign-on tab, copy the values of these fields from the Unity card:
- Entity ID
- Login URL, also known as the Assertion Consumer Service (ACS) URL
- Certificate
-
Go back to your IdP portal and paste the values in the corresponding fields of the SAML settings.
-
Add custom user attribute mapping to your SAML 2.0 connector in your IdP:
- For the custom attribute name, enter Email.
- Select the user's email address in the IdP as the field.
Add your IdP settings to Unity
To add the settings of your IdP to Unity, follow these steps:
-
From the settings page of your SAML application, generate the following metadata parameters of the application:
- Entity ID: the IdP that you're using. This parameter might be named identity provider issuer or issuer URL.
- SSO Login URL: the IdP login URL.
- X.509: the IdP certificate.
-
In the Unity Dashboard, open the Account menu and select Manage organization.
-
In the Administration menu, select SSO & SCIM.
-
On the Single Sign-on tab, find the Identity Provider card and select Edit.
-
Paste the values in the corresponding fields, and then save your changes.
Enable Enterprise SSO
Enable Enterprise SSO to make SSO available to your users. All users in your validated domains can then sign in with the Enterprise SSO authentication method and be authenticated by your IdP. When a user signs in to Unity this way for the first time, Unity provisions a Unity account for them Just-in-Time (JIT) so that they can onboard immediately.
To enable Enterprise SSO, complete these steps:
-
In the Unity Dashboard, open the Account menu and select Manage organization.
-
In the Administration menu, select SSO & SCIM.
-
On the Single Sign-on tab, under step 2, Enable Enterprise Single Sign-on, turn on the setting.The status changes from Disabled to Enabled.
Test the SAML SSO integration
To test the SAML SSO integration, sign in to Unity using the SSO flow in one of the following ways.
Sign in to your IdP application directory
-
Go to your IdP application directory.
-
Select the Unity application.This flow redirects you to the IDP's sign-in page.
-
Enter the email for a test user, and then select Sign in.Your test account is now logged into Unity.
Sign in to Unity Cloud
-
Sign out of Unity Cloud.
-
Go to the Unity Dashboard.
-
Select Sign in, and then select Sign in with Enterprise SSO.This flow redirects you to the IDP's sign-in page.
-
Enter the email for a test user, and then select Sign in.Your test account is now logged into Unity.
Enforce SSO authentication
Enabling Enterprise SSO lets users log in with SSO, but they're not mandated to use it. For information on when it's required and how to exempt specific users from the requirement, refer to Enforce SSO authentication.
Disable Enterprise SSO
Disabling Enterprise SSO also disables SCIM provisioning, SSO authentication enforcement, and SCIM provisioning enforcement, because all three depend on Enterprise SSO.
To disable Enterprise SSO, complete these steps:
-
In the Unity Dashboard, open the Account menu and select Manage organization.
-
In the Administration menu, select SSO & SCIM.
-
On the Single Sign-on tab, under step 2, Enable Enterprise Single Sign-on, turn off the setting.The status changes from Enabled to Disabled.
Considerations
When integrating Unity SSO with your IdP, consider these points:
- When users create a Unity ID account through SSO, Unity doesn't create a password for the user. If the user later wants to log in with a password, they must select Forgot your password? and set up their password.
- When signing in through SSO, users are automatically assigned to the organization for which SSO is set up. After sign-in, users can switch organizations and access the other organizations which they're a member of.