Documentation Index

Fetch the complete documentation index at: https://support.fullcast.com/llms.txt

Use this file to discover all available pages before exploring further.

Configure SSO

Prev Next

Configure Single Sing-On (SSO) with Fullcast using a SAML 2.0 Identity Provider (IdP).

Note

IdP-initiated Single Sign-on is not supported.

Supported features

  • Service provider (SP)-initiated only: You must first login to Fullcast to begin the SSO login process. The SSO app panel can use a bookmark app to allow login from the app directory.

  • Just-in-Time (JIT) provisioning: Fullcast supports automatic user provisioning upon initial login through SSO.

  • User access management: User access within Fullcast is managed through the Fullcast user management settings panel.

  • System for Cross-domain Identity Management (SCIM) provisioning: Automates the exchange of user identity information between Fullcast and your IdP.

Before you begin

  • Login to your IdP: You must be logged in so you can update the settings for SSO with Fullcast.

  • Copy your domain URL: Your domain URL is required to configure SSO in Fullcast.

Configure SSO

  1. Access your Fullcast instance.

  2. Go to Settings > Authentication.

  3. Under Authentication, select Single Sign-On.

  4. In the field, paste your domain URL.

  5. Click Configure SSO.

  6. In the Configure Single Sign-On window, click Get Started.

  7. Select Custom SAML then click Next.

Create an application

  1. On the Create an Application step, copy the Single Sign-On URL and paste in corresponding field in your IdP.

  2. Copy the Service Provider Entity ID and paste in corresponding field in your IdP.

  3. Click Next.

Configure your connection

You can choose to configure your connection automatically in Fullcast or manually. From the Configure Connection step, select one of the following tabs and complete the steps.

Configure Advanced Settings

The Advanced Settings are optional, but recommended. The SAMLP and Sign Request option automatically signs the SAML authentication request.

Note

You are not required to select Sign Request and the SSO connection will still work if this is not enabled.

  1. Expand the Advanced Settings.

  2. Select Sign Request.

  3. Keep the default selections in the Sign Request Algorithm, Sign Request Algorithm Digest, and Request Protocol Binding dropdowns.

  4. Click certificate to download the certificate from Fullcast.

  5. In your IdP, enable SAMLP and upload the certificate.

  6. Click Create Connection.

  7. In the confirmation window, click Proceed.

Test SSO connection

  1. From the Test SSO step, click Test Connection.

  2. Check the JSON displayed to ensure the correct user attributes are being passed.

  3. Click Enable Connection.

  4. In the Proceed to enable the connection confirmation window, click Proceed.

Configure IdP settings

Check the following configurations in your IdP which are required for SSO with Fullcast. Refer to your IdP's user documentation for support, as needed.

User accounts when SSO is disabled

Disabling SSO changes how users authenticate — it does not remove existing user accounts from Fullcast. User tiles remain in User Management after SSO is turned off.

Note

If SCIM is configured alongside SSO, users removed from your IdP are automatically synced and deprovisioned in Fullcast. Disabling SSO entirely does not trigger a bulk removal of all user accounts.

To remove a user tile after disabling SSO, a tenant admin or sys admin must manually delete or block the user. Go to Settings > User Management, find the user, click the menu , and select Delete or Block User. Refer to Manage existing users for more information.