Enabling SSO for Satellite Accounts

When you have satellite accounts connected to your hub account, you can administer them from the hub account level.

Single Sign-On is a Select and Premium feature so Single Sign-On can only be enabled on satellites that are on Select and Premium plans.

  1. Click Settings > Account settings (1).

  2. Click the satellite account in the drop down menu (2).

  3. Open the Single Sign-On tab (3).

  4. Start editing the SSO configuration (4).

  5. Enabling_SSO_-_Satellite_Account.png
    Here you will have two methods (5) of configuration:

  6. Inherited: SSO with the configuration taken from your hub account.
    If a user accesses Workfront Proof through the default login page (https://www.proofhq.com/login) there will be two levels of authorization: First a user is asked to log in using Workfront Proof access data (email and password); then the user is transferred through an SSO window to the SSO login page.
    Therefore, with SSO service enabled, we recommend to log in through your own Workfront Proof sub-domain/domain.

    NOTE
    At this time, when Single Sign-On is enabled on your Workfront Proof account, you will not be able to log in to the iPhone app with those credentials.
    1. Manual (default): SSO with a different configuration (for example, pointing to another Identity Provider).

      NOTE
      If the satellite account is inheriting the SSO configuration from the hub account, the login screen will be that of the hub account. When the satellite account user enters their SSO login details on this page, they will be re-directed back to the satellite account.

      Enabling_SSO_-_Satellite_Account_2.png

    2. Click Save (6).

SSO Settings Inherited from a Hub Account

When you choose to inherit the settings from your hub account you’ll notice that all the fields are now populated with the data from your hub account (7) and that Single Sign-On is automatically Enabled/Disabled(8) as on your main account. There are also no edit links in the fields anymore, as the whole SSO configuration for the Satellite Account is now set and managed from your hub account.

Satellite_Account_-_Inherited_SSO.png

In your hub account (9) the SSO Usage field shows that this configuration is in use by satellite accounts (10).
Hub_Account_-_Inherited_SSO.png

SSO Configured Manually

If Manual SSO configuration has been chosen for a satellite account (1), you need to manually enter the data for the Single Sign-On.

  1. Click Settings > Account settings (1).

  2. Open the Single sign-on tab.

  3. Click Edit, populate the field and then click Save (2).

  4. On the SSO row, click Enabled (3).

Satellite_Account_-_Manual_SSO.png

SSO Log In

  1. Click Settings > Account settings (1).

  2. Open the Single sign-on tab.

  3. Make sure that your Workfront Proof domain/sub-domain (1) is set up and that your users access your Workfront Proof account through this customized domain/sub-domain.
    SAML_Subdomain.png
    With your Single Sign-On enabled, your sub-domain login URL (e.g. yourcompany.proofhq.com/login) displays a transfer screen (2) that takes you directly to your SSO login page.
    SSO_login_page.png

  4. If a user accesses Workfront Proof through the default log in page (https://www.proofhq.com/login) there will be two levels of authorization. First a user is asked to log in using Workfront Proof access data (email and password). Then, the user is transferred through an SSO window (2) to the SSO login page.
    Therefore, with SSO service enabled, we recommend to log in through your own Workfront Proof sub-domain/domain.

  5. At this time, when Single Sign-On is enabled on your Workfront Proof account, you will not be able to log in to the iPhone app with those credentials.

About Adding a New User

When the Single Sign-On functionality is enabled on your Workfront Proof account, new users will not receive any confirmation emails as their accounts will be automatically activated and ready to use.

From your Workfront Proof log in page, after clicking the Login button, users are taken to your SSO login page and asked to enter your Single Sign-On login credentials.

IMPORTANT
Users are identified through an email address during the authentication process, which means the email account used for your SSO login must be the email address of the user registered within your account.

Active Directory Federation Services (AD FS)

The Active Directory Federation Services (AD FS) is a Microsoft software component that can be installed on Windows Server operating systems to provide users with Single Sign-On access to systems and applications located across organizational boundaries. For more information, see “Active Directory Federation Services” on the Microsoft Developer Network website.

The Workfront Proof system supports SAML 2.0 and is only compatible with AD FS version 2.0 or greater.

See Single Sign-On in Workfront Proof: AD FS configuration for detailed instructions.

Previous pageConfigure custom profiles in Workfront Proof
Next pageSingle Sign-On in Workfront Proof: AD FS configuration

Workfront