Workspace Single Sign-On Settings
Settings that can be used with Single Signon
Path: Workspace Homepage >> Navigation Panel >> Settings >> Security >> Authentication >> Single Signon Settings
| What are Workspace Single Sign-On Settings? |
| Workspace Single Sign-On Settings are the workspace-level options that control how Single Sign-On (SSO) behaves once an identity provider connection has been established, including SSO type, login behavior, username handling, and Trusted Domains. |
Single Sign-On (SSO) is a method of integrating an organization's existing user directory with IdeaScale's authentication system. Configuring SSO removes the need for a member to log in to IdeaScale with a separate set of credentials — access to the community is instead determined by the member's existing access to the organization's intranet, removing a login step that many Workspace Administrators consider a barrier to participation.

Role Permissions
- Workspace Administrator: Configures the Single Sign-On type (SAML 2.0, Token-Based/Multipass, or Azure AD) and the General Settings that control SSO login behavior, username handling, and Trusted Domains.
- Community Administrator: Can choose to enable or disable the SSO set up by Workspace admin for their community.
- Member: Logs in using whichever Single Sign-On method the Workspace Administrator has enabled for the workspace, or with an IdeaScale Email/Password login if Allow to Access IdeaScale Profile is enabled.
Types of Single Sign-On
IdeaScale offers three types of Single Sign-On, each suited to a different method of connecting an organization's existing identity system to IdeaScale.
SAML 2.0
SAML (Security Assertion Markup Language) is an XML-based standard for exchanging authentication and authorization data between an identity provider (IdP), such as Okta, and a service provider (SP). For IdeaScale SSO integrations, the IdeaScale community serves as the service provider.
Help Article for Okta Configuration Process
Help Article for SAML Single Sign-On at IdeaScale
Token-Based/Multipass
Multipass authentication is a single sign-on strategy that allows an organization to share its user authentication with IdeaScale through an encrypted token, passed either in the URL or as a parameter in a POST form.
Help Article for Token-Based/Multipass SSO
Azure AD
Azure AD determines which members have access to IdeaScale and helps manage accounts from a single central location — the Azure portal.
Help Article for Azure Active Directory Integration
General Settings
Once a Single Sign-On type is connected, the following options are available under General Settings to control how SSO behaves for the workspace.
- Remove Sync groups when groups are empty: Removes any groups that have no members assigned to them.
- Want Assertion Signing: Controls whether the SAML response, the assertions, or both must be signed, set to True or False in the XML data. Signing both the response and the assertions is redundant, so signing only one is typically sufficient (TO BE VERIFIED — source wording for this field is ambiguous about which combination is required).
- Authn Requests Signed: Uses the private key associated with the local certificate (for example, an SP.PFX file) to sign the authentication request. The identity provider (IdP) must be configured with the corresponding certificate.
- Allow to Access IdeaScale Profile: Allows a member to log in using IdeaScale credentials in addition to the option to log in through SSO (TO BE VERIFIED — source spells this field "Ideascale Profile"; confirm exact on-screen capitalization).
- Redirect to SSO Login Automatically: When enabled, automatically redirects the SSO-enabled community to the SSO login page.
- Login Redirection Delay (in seconds): Sets a delay, in seconds, before the automatic redirect to the SSO login page occurs. The value must be greater than 0; the default value is 5.
- Display buttons instead of a dropdown menu for multi-SSO setup: When enabled, displays the available SSO options as buttons rather than as a dropdown menu.
- Allow members/persons to change username: Allows a member of an SSO-enabled community to change the username that was passed to IdeaScale through SSO.
- Trusted Domains: Specifies email domains that are automatically treated as verified by the system for SSO-enabled communities.
Note: The Workspace Administrator must contact the IdeaScale Innovation Architect to add Trusted Domains for the Workspace.
Frequently Asked Questions
What is the difference between SAML 2.0, Token-Based/Multipass, and Azure AD?
SAML 2.0 exchanges authentication and authorization data between an identity provider, such as Okta, and IdeaScale as the service provider. Token-Based/Multipass shares user authentication through an encrypted token passed in the URL or a POST form. Azure AD manages which members have access to IdeaScale from a single central location, the Azure portal.
Can a member still log in with IdeaScale credentials when SSO is enabled?
Yes, if the Workspace Administrator has enabled Allow to Access IdeaScale Profile, a member has the option to log in with IdeaScale credentials in addition to logging in through SSO.
What happens when Redirect to SSO Login Automatically is enabled?
The SSO-enabled community is automatically redirected to the SSO login page after the configured Login Redirection Delay, which must be greater than 0 seconds and defaults to 5 seconds.
Can a member change the username that was passed to IdeaScale through SSO?
Yes, if the Workspace Administrator has enabled Allow members/persons to change username.
How are Trusted Domains added for an SSO-enabled workspace?
The Workspace Administrator must contact the IdeaScale Innovation Architect, who adds the Trusted Domains for the Workspace.
Related Articles
- Help Article for Workspace Authentication
- Help Article for SCIM in IdeaScale
- Help Article for SSO Debugger
- Help Article for Okta Configuration Process
- Help Article for SAML Single Sign-On at IdeaScale
Last Updated: August 14, 2026