--- title: "SSO - SAML Settings" slug: "sso-saml-settings" updated: 2024-09-26T15:15:56Z published: 2024-09-26T15:15:56Z canonical: "docs.processmaker.com/sso-saml-settings" --- > ## Documentation Index > Fetch the complete documentation index at: https://docs.processmaker.com/llms.txt > Use this file to discover all available pages before exploring further. # SSO - SAML Settings > [!TIP] > [**Plan Availability:**](https://www.processmaker.com/products/pricing/) ![Professional](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/Standard.png)![Professional](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/Professional.png)![Enterprise](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/Enterprise.png) ## Configure SSO SAML Settings **Permissions** Your user account or group membership must have the "Settings: Update Settings" permission to edit SSO SAML settings unless your user account has the **Make this user a Super Admin** setting selected. See the [Settings](/v1/docs/permission-descriptions-for-users-and-groups#settings) permissions or ask your Administrator for assistance. > [!NOTE] > #### Notice to Administrators > > Enhance security for your ProcessMaker Platform instance by following [these best practices](/v1/docs/enhance-processmaker-platform-security). It is recommended to require all ProcessMaker users to log in using Single Sign-On (SSO), OAuth, OKTA, and/or two-factor authentication (2FA). The following information is required to configure SSO with SAML: - SSO endpoint - SSO identifier - SLO endpoint - Encryption type - Authentication context - Public certificate - Name ID format To generate or locate this information, contact your SAML identity provider. > [See an example how to configure SSO SAML with Microsoft Entra ID](/v1/docs/example-saml-with-microsoft-entra-id). Watch the following video for an example of how to configure SAML SSO settings. - **Intended audience:** System administrators and Process designers - **Viewing time:** 6 minutes; contains narration [Embedded content](https://cdn.iframe.ly/gafJ59Q) Follow these steps to configure SAML SSO settings: 1. [Configure your SSO Settings](/v1/docs/sso-settings#configure-sso-saml-settings). 2. From the list of SSO identity providers, select the **SAML** option. The **SSO - SAML** tab displays. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/00f83d78-0e72-452b-9b8b-005fe1225133.png) 3. Use the copy icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/441d4c20-b0b2-4546-8394-a6bcdcc309bd.png) to copy the URL from the **ACS Url** setting, and then provide it to your SAML identity provider. 4. Use the copy icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/441d4c20-b0b2-4546-8394-a6bcdcc309bd.png) to copy the URL from the **Entity ID (Metadata)** setting, and then provide it to your SAML identity provider. 5. Use the copy icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/441d4c20-b0b2-4546-8394-a6bcdcc309bd.png) to copy the URL from the **Single Logout URL** setting, and then provide it to your SAML identity provider. 6. Click the **Edit** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/829a71fe-01c2-47b8-b221-747ca5f44809.png) for the **SSO Endpoint** setting. The **SSO Endpoint** screen displays. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/e13be16b-ea78-4045-ab4b-92f028acb225.png) 7. Enter the identity provider URL from which ProcessMaker retrieves the authentication response and validates it when establishing the SSO session. Your identity provider provides this URL. 8. Click the **Edit** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/829a71fe-01c2-47b8-b221-747ca5f44809.png) for the **SSO Identifier** setting. The **SSO Identifier** screen displays. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/69180616-9009-489c-95ba-fce3dc8fd682.png) 9. Enter the URL that references the SAML XML file for your identity provider (IdP). Your identity provider provides this URL. 10. Click the **Edit** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/829a71fe-01c2-47b8-b221-747ca5f44809.png) for the **SLO Endpoint** setting. The **SLO Endpoint** screen displays. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/c0a7f19c-1edb-406c-9af6-26ff192be60c.png) 11. Enter the logout URL provided by your identity provider. 12. Click the **Edit** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/829a71fe-01c2-47b8-b221-747ca5f44809.png) for the **Encryption Type** setting. The **Encryption Type** screen displays. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/22d6b0e9-0678-45ea-9136-22ecae44527b.png) 13. From the list of encryption types, select the encryption type your identity provider uses. 14. Use the **Authentication Context** toggle to indicate whether to send authentication context in the authorization request or not. 15. Click the **Edit** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/829a71fe-01c2-47b8-b221-747ca5f44809.png) for the **Public Certificate** setting. The **Public Certificate** screen displays. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/42e54f39-f18c-46e5-9f2f-de1be0cf4006.png) 16. Enter the identity provider's certificate fingerprint by pasting it into this setting. Your identity provider provides this certificate. Ensure to include the **-----BEGIN CERTIFICATE-----** header. ProcessMaker retrieves the authentication response and validates it using the identity provider's certificate fingerprint. 17. Click the **Edit** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/829a71fe-01c2-47b8-b221-747ca5f44809.png) for the **File crt** setting. The **File crt** screen displays. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/e2338caf-2370-460d-8f0e-8f51be2588e0.png) 18. Click the browse button and then select the file containing your SAML certificate, if one is available from your identity provider. 19. Click the **Edit** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/829a71fe-01c2-47b8-b221-747ca5f44809.png) for the **File key** setting. The **File key** screen displays. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/e2338caf-2370-460d-8f0e-8f51be2588e0.png) 20. Click the browse button and then select the file containing your SAML key, if one is available from your identity provider. 21. Click the **Edit** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/829a71fe-01c2-47b8-b221-747ca5f44809.png) for the **User Matching** setting. The **User Matching** screen displays. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/9fd9d252-7218-456e-9375-61aab4ce524b.png) 22. Click the **Add** button. An empty row displays. 23. In the **ProcessMaker Property** setting, enter the ProcessMaker user property to which to match the SSO SAML attribute. 24. In the **SAML Attribute** setting field, enter the SSO SAML attribute from which to map to the ProcessMaker user property. 25. Optionally, click the **Delete** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/5cf87115-95cc-47a9-9912-abcdb616e4c2.png) to delete a mapped ProcessMaker user property. 26. Click **Save**. The following message displays: **The setting was updated.** 27. Click the **Edit** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/829a71fe-01c2-47b8-b221-747ca5f44809.png) for the **Variable Map** setting. The **Variable Map** screen displays. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/e0814de5-fdd0-4637-acec-9b949fb8f032.png) 28. Click the **Add** button. An empty row displays. 29. In the **ProcessMaker Property** setting, enter the ProcessMaker user property to which to match the SSO SAML attribute. 30. In the **SAML Attribute** setting, enter the SSO SAML attribute from which to map to the ProcessMaker user property. 31. Optionally, click the **Delete** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/5cf87115-95cc-47a9-9912-abcdb616e4c2.png) to delete a mapped ProcessMaker user property, . 32. Click **Save**. The following message displays: **The setting was updated.** 33. Click the **Edit** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/829a71fe-01c2-47b8-b221-747ca5f44809.png) for the **Name ID Format** setting. The **Name ID Format** screen displays. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/22d889b7-569f-4844-a43c-d0e22b2f4c5a.png) 34. Enter the name identifier format supported by your SAML identity provider. ## Related - [SSO Settings](/sso-settings.md)