Steps: Configure Single Sign-On (SSO) for Contract Management and Document Intelligence
- Your Identity Provider (IdP) must support SAML 2.0.
- Enable the owner, admin, or custom role with theSingle Sign-On (SSO): Manage permissionin Contract Management and Document Intelligence.
You can set up SSO to enable users to access Contract Management and Document Intelligence using their existing identity provider credentials. This simplifies the login process for users by eliminating the need to remember separate usernames and passwords. SSO enhances security by centralizing authentication through a trusted identity provider.
Depending on the identity provider you choose, specific configuration details and considerations may apply. Refer to the provider specific content for more information:
- In your Identity Provider (IdP), sign in as an administrator.
- Add a new SAML application.
- SelectSAML 2.0.
- Enter these details:
Option Description Application NameContract Management and Document Intelligence(Optional)Application LogoYou can link the Contract Management and Document Intelligence logo. - In Contract Management and Document Intelligence, enable SSO.
- ClickAdmin.
- ClickSingle Sign-On.
- ClickAdd Configuration.
- Copy these values and paste them into the IdP SSO configuration:
- Assertion consumer service (ACS) URL:The IdP uses the ACS URL to redirect authenticated users after signing in.
- Service provider (SP) entity ID:Contract Management and Document Intelligence uses the SP identity ID as a unique identifier. Workday doesn’t support setting up SSO in multiple workspaces as the Entity ID is the same.
- In your IdP SSO configuration, find these details and enter them in Contract Management and Document Intelligence
Option Description IdP nameThe name of your Identity Provider. This is for display purposes only on the Workday sign-in page.SSO URL (SAML 2.0 Endpoint)The URL where Contract Management and Document Intelligence redirects users to sign in to your IdP.IdP ID (Identity Provider Issuer or Entity ID)Your IdP unique identifier.(Optional)IdP metadata URLEnter this if your X.509 Certificate is variable or rotating. In some cases, providing this information may eliminate the need to enter the X.509 certificate directly, but this depends on your setup. - In your IdP, open the metadata XML file, copy the X.509 certificate code and paste it into Contract Management and Document Intelligence.You can find the X.509 code between theBegin CertificateandEnd Certificatefields, but don’t copy the field names.
- In Contract Management and Document Intelligence, selectAuthentication context class.
- In your IdP, configureAttribute mappings.Copy these attribute names or URLs from your IdP and paste them into Contract Management and Document Intelligence:
- Email
- First name
- Last name
- Job title
- Department
- Role
Attributes are typically plain text. However, if your IdP is a Microsoft self-hosted server or cloud server (Azure), the attributes might format as URLs. Because attribute field names can be customized or overwritten, verify the exact field names used in your specific setup.You can assign multiple departments to the same user. Create a new field designed to store acomma-separated string arrayof department names. Example: ["Department1", "Department 2", "Department 3"]. The departments must already exist in Contract Management and Document Intelligence for the user to successfully sign in. - In Contract Management and Document Intelligence, selectEnable SSO.
- Select which users must use SSO to sign in. If you select enforcing SSO for all users, the recommended method for user provisioning is to create or assign the user directly in the Identity Provider (IdP).
- Assign a default role to new users who sign in through SSO.