Configure Single Sing-On (SSO) with Fullcast using a SAML 2.0 Identity Provider (IdP).
Note
IdP-initiated Single Sign-on is not supported.
Supported features
Service provider (SP)-initiated only: You must first login to Fullcast to begin the SSO login process. The SSO app panel can use a bookmark app to allow login from the app
directory.Just-in-Time (JIT) provisioning: Fullcast supports automatic user provisioning upon initial login through SSO.
User access management: User access within Fullcast is managed through the Fullcast user management settings panel.
System for Cross-domain Identity Management (SCIM) provisioning: Automates the exchange of user identity information between Fullcast and your IdP.
Before you begin
Login to your IdP: You must be logged in so you can update the settings for SSO with Fullcast.
Copy your domain URL: Your domain URL is required to configure SSO in Fullcast.
Configure SSO
Access your Fullcast instance.
Go to Settings > Authentication.
Under Authentication, select Single Sign-On.
In the field, paste your domain URL.
Click Configure SSO.
In the Configure Single Sign-On window, click Get Started.
Select Custom SAML then click Next.
Create an application
On the Create an Application step, copy the Single Sign-On URL and paste in corresponding field in your IdP.
Copy the Service Provider Entity ID and paste in corresponding field in your IdP.
Click Next.
Configure your connection
You can choose to configure your connection automatically in Fullcast or manually. From the Configure Connection step, select one of the following tabs and complete the steps.
Configure Advanced Settings
The Advanced Settings are optional, but recommended. The SAMLP and Sign Request option automatically signs the SAML authentication request.
Note
You are not required to select Sign Request and the SSO connection will still work if this is not enabled.
Expand the Advanced Settings.
Select Sign Request.
Keep the default selections in the Sign Request Algorithm, Sign Request Algorithm Digest, and Request Protocol Binding dropdowns.
Click certificate to download the certificate from Fullcast.
In your IdP, enable SAMLP and upload the certificate.
Click Create Connection.
In the confirmation window, click Proceed.
Test SSO connection
From the Test SSO step, click Test Connection.
Check the JSON displayed to ensure the correct user attributes are being passed.
Click Enable Connection.
In the Proceed to enable the connection confirmation window, click Proceed.
Configure IdP settings
Check the following configurations in your IdP which are required for SSO with Fullcast. Refer to your IdP's user documentation for support, as needed.
User accounts when SSO is disabled
Disabling SSO changes how users authenticate — it does not remove existing user accounts from Fullcast. User tiles remain in User Management after SSO is turned off.
Note
If SCIM is configured alongside SSO, users removed from your IdP are automatically synced and deprovisioned in Fullcast. Disabling SSO entirely does not trigger a bulk removal of all user accounts.
To remove a user tile after disabling SSO, a tenant admin or sys admin must manually delete or block the user. Go to Settings > User Management, find the user, click the menu ⋮, and select Delete or Block User. Refer to Manage existing users for more information.