> ## Documentation Index
> Fetch the complete documentation index at: https://moengage-user-guide.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Single Sign-On (SSO)

Single Sign-On (SSO) is a system that allows you to use one set of login credentials to access multiple applications without having to re-enter their credentials for each individual application. With SSO, you can easily access the MoEngage dashboard using your organization's central identity provider (IdP).

## Advantages of SSO

The advantages of using SSO include:

* **Simplified user experience**: SSO eliminates the need for users to remember and manage multiple usernames and passwords for different applications, making the login process much easier and faster.
* **Reduced password fatigue**: By consolidating credentials, SSO reduces the burden on users to remember and manage numerous passwords, which can lead to security risks and frustration.
* **Enhanced security**: Centralized authentication with SSO allows for more effective security controls, such as stronger password policies and multi-factor authentication, and simplifies the process of managing user access and permissions.
* **Improved productivity**: SSO allows users to spend less time on login processes and more time on core work tasks, leading to increased productivity and efficiency.
* **Reduced IT costs**: SSO streamlines user access management, reducing the workload for IT teams and minimizing the need for password resets and support calls, leading to cost savings.

## SSO Configuration

MoEngage supports SSO using Security Assertion Markup Language (SAML) 2.0 and acts as an SSO service provider (SP). SAML is an industry-standard protocol that enables user authentication delegation similar to OAuth 2.

Upon login, you are redirected to your internal or external SSO system for authentication and then returned to MoEngage when the response is verified.

<img src="https://mintcdn.com/moengage-user-guide/qw5XrN_cv6pHJ-Hs/images/moengage_266f51.png?fit=max&auto=format&n=qw5XrN_cv6pHJ-Hs&q=85&s=3dcd8e816723307b719586937c3aca4e" alt="Screenshot_2022-10-18_at_9.39.29_AM.png" width="1864" height="1326" data-path="images/moengage_266f51.png" />

<Info>
  * Contact your organization's IT team to set up SSO to log in to the MoEngage dashboard.
  * Only administrators can enable SSO for a workspace, which allows their teammates to log in securely using the identity provider credentials.
  * To configure SSO, you need an Admin role with the **Setup & manage** permission for the **Login Settings** component.\
    Note: The **Login Settings** is now renamed to **Security Settings**.
</Info>

# Identity Providers (IdPs)

MoEngage uses Identity Providers (IdPs) to simplify and centralize user login. This allows you to securely access MoEngage services using SSO based on the SAML 2.0 standard. MoEngage supports the following IdPs currently:

* Okta
* Onelogin
* Azure (Microsoft Entra ID)
* Google Admin
* Other (you can configure other IdPs, provided they are SAML 2.0 compliant)

To enable SSO in the MoEngage dashboard, perform the following steps:

1. On the left navigation menu in the MoEngage dashboard, click **Settings** > **Account** > **Security**. <img src="https://mintcdn.com/moengage-user-guide/vbW0L13jO4xtQMap/images/moengage_7979c2.png?fit=max&auto=format&n=vbW0L13jO4xtQMap&q=85&s=82ce11f58ba3b2dfd46d8fed555fa412" width="2880" height="1538" data-path="images/moengage_7979c2.png" />
2. On the Security page, click the **Login** tab.
3. Click **Single Sign On (SSO) only**.
4. Under **Single sign on**, click **Configure SSO**. <img src="https://mintcdn.com/moengage-user-guide/5A129BX8ihFPPDOM/images/moengage_f5d80e.png?fit=max&auto=format&n=5A129BX8ihFPPDOM&q=85&s=8d1ece7b5a839cc1fac0d337d9f8734b" width="1748" height="1268" data-path="images/moengage_f5d80e.png" /> The **Configure SSO** dialog box appears.
5. In the **Identity Provider** list, select your identity provider. <img src="https://mintcdn.com/moengage-user-guide/-3vSwXDB0-23wJct/images/moengage_b511a8.png?fit=max&auto=format&n=-3vSwXDB0-23wJct&q=85&s=0b4468b1d8389704b4e89af1065416a6" width="2290" height="1366" data-path="images/moengage_b511a8.png" /> Now, you must switch to that specific IdP admin console to configure the SSO settings and ensure the SSO integration between MoEngage and the selected IdP functions as intended.
   <Info>
     If your preferred identity provider is not available in the **Identity Provider** list, you can select *Other* to configure your SSO. This function works with any SAML 2.0-compliant provider.
   </Info>

<Tabs>
  <Tab title="Configure Okta SSO">
    To set up SSO with Okta, perform the following steps:

    1. Navigate to the **Okta Admin Console**.
    2. On the left navigation menu, click **Applications** > **Applications**. <img src="https://mintcdn.com/moengage-user-guide/f9utDwqBcydYgMUJ/images/moengage_430dce.png?fit=max&auto=format&n=f9utDwqBcydYgMUJ&q=85&s=ecd9436ac8fbbf86c7d53b449307223f" width="2808" height="1332" data-path="images/moengage_430dce.png" />
    3. On the **Applications** page, click **Create App Integration**. <img src="https://mintcdn.com/moengage-user-guide/xi-Qv9dxzHCirerU/images/moengage_fbb92e.png?fit=max&auto=format&n=xi-Qv9dxzHCirerU&q=85&s=cdeceb6bd4f308f157737fa2764267d7" width="2810" height="1238" data-path="images/moengage_fbb92e.png" /> \
       The Create a new app integration pop-up window appears.
    4. Click the **SAML 2.0** option and then click **Next**. <img src="https://mintcdn.com/moengage-user-guide/5GL696t-Fqf2hfA3/images/moengage_a8ff78.png?fit=max&auto=format&n=5GL696t-Fqf2hfA3&q=85&s=b99cf253c119f0c65018e37b57be48c4" width="1934" height="1138" data-path="images/moengage_a8ff78.png" /> The Create SAML integration page appears. You are taken to the first step, **General Settings**, to define your app. <img src="https://mintcdn.com/moengage-user-guide/8Ml9Ic0RRLLTTfx5/images/moengage_b71248.png?fit=max&auto=format&n=8Ml9Ic0RRLLTTfx5&q=85&s=e5914e30266225f1413a686ce6c2ec8d" width="2812" height="1190" data-path="images/moengage_b71248.png" />
    5. Enter the following details:
       | Field          | Required | Description                                                                                                                                    |
       | -------------- | -------- | ---------------------------------------------------------------------------------------------------------------------------------------------- |
       | App name       | Yes      | Type your app name.                                                                                                                            |
       | App logo       | Optional | Upload an image file (typically PNG, JPG, or GIF) to serve as your application icon. <br />**Note**: The image file must be smaller than 1 MB. |
       | App visibility | Optional | Select the **Do not display application icon to users** check box adjacent to **App Visibility** to hide the application icon from the users.  |
    6. Click **Next.** You will move to the second step, **Configure SAML**, to define the SAML settings.
    7. On the **Configure SSO** dialog box in the MoEngage dashboard, copy the **Single sign-on URL** and **Audience URI (SP Entity ID)**. <img src="https://mintcdn.com/moengage-user-guide/m0UHvXd8pax8UuCU/images/moengage_4b2e97.png?fit=max&auto=format&n=m0UHvXd8pax8UuCU&q=85&s=517fb84929c69fdabf802e2c1ce9723b" width="2416" height="1428" data-path="images/moengage_4b2e97.png" />
    8. Under **SAML Settings**, enter the following details:
       | Field                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | Required | Description                                                                                                                                                                                                                                                                          |
       | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
       | Single Sign-On URL                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | Yes      | This URL receives the SAML assertion (the authentication response) from Okta to MoEngage.  Paste the URL copied from the MoEngage dashboard.                                                                                                                                         |
       | Audience URI (SP Entity ID)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Yes      | This URL informs Okta about the specific application (MoEngage) for which the authentication assertion is intended.  Paste the URI copied from the MoEngage dashboard.  <br />**Note**: In this box, you can add multiple entity IDs from different workspaces, separated by commas. |
       | Name ID format                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | Yes      | Select *EmailAddress*.                                                                                                                                                                                                                                                               |
       | <img src="https://mintcdn.com/moengage-user-guide/nZjfcQvhlPk8hZQk/images/moengage_a05404.png?fit=max&auto=format&n=nZjfcQvhlPk8hZQk&q=85&s=157c93ee51df5fcefa31fa5a0b4a93ac" alt="" width="2806" height="1164" data-path="images/moengage_a05404.png" /> |          |                                                                                                                                                                                                                                                                                      |
    9. Scroll to the end of the page and click **Next**. You are taken to the third step, **Feedback**.
    10. Select the **This is an internal app that we have created** check box adjacent to the **App type**. <img src="https://mintcdn.com/moengage-user-guide/g5z_bz8PEWXqJHJ6/images/moengage_9b3fe7.png?fit=max&auto=format&n=g5z_bz8PEWXqJHJ6&q=85&s=d5d4453a26dc1fcca334bd581571697e" width="2804" height="982" data-path="images/moengage_9b3fe7.png" />
    11. Click **Finish**. You must now generate the **SAML Signing Certificates** to connect your app to Okta.
    12. By default, you are on the **Sign On** tab. Scroll to the end of the page, and under **SAML Signing Certificates**, find the **Status** marked as *Active* to download the certificate.
    13. Click the **Actions** arrow in the **Actions** column.
    14. Click **Download certificate**. <img src="https://mintcdn.com/moengage-user-guide/FbErsVdzNV9sOQk9/images/moengage_65d962.png?fit=max&auto=format&n=FbErsVdzNV9sOQk9&q=85&s=645d34d490b5982231f3879356da1302" width="2878" height="1306" data-path="images/moengage_65d962.png" /> The metadata will be downloaded in an XML file.
    15. Upload the downloaded XML file in the **Enter XML Configuration** box on the **Configure SSO** dialog box of the MoEngage dashboard.
    16. By default, the **Update the same config for Test Environment** check box is selected. When it is selected, the configuration is applied to both the test and live environments. Clear the check box if you want the configuration to be applied only to the live environment.
    17. Click **Configure**. <img src="https://mintcdn.com/moengage-user-guide/8Ml9Ic0RRLLTTfx5/images/moengage_b6fce2.png?fit=max&auto=format&n=8Ml9Ic0RRLLTTfx5&q=85&s=221245a02998e4858f228e7675215545" width="1756" height="1198" data-path="images/moengage_b6fce2.png" /> The Alert pop-up window will appear, prompting you to review the instructions properly.
    18. Select the **Send email to the users of this workspace** check box to notify all users about your workspace's Single Sign-On (SSO) enablement.
    19. Click **Done**. <img src="https://mintcdn.com/moengage-user-guide/UOu66ZvIudsFME7I/images/moengage_3c648e.png?fit=max&auto=format&n=UOu66ZvIudsFME7I&q=85&s=52e390489f6ceef96ae62d118223bb81" width="2008" height="1006" data-path="images/moengage_3c648e.png" /> The SSO configuration is now successfully completed. You can see the Okta SSO on the **Login** tab. <img src="https://mintcdn.com/moengage-user-guide/5A129BX8ihFPPDOM/images/moengage_f5bdef.png?fit=max&auto=format&n=5A129BX8ihFPPDOM&q=85&s=22e3771af29932181d17e6ff5279d6da" width="2072" height="1226" data-path="images/moengage_f5bdef.png" />
  </Tab>

  <Tab title="Configure Onelogin SSO">
    To set up SSO with Onelogin, perform the following steps:

    1. Navigate to the **Onelogin Admin Console**.
    2. Click **Administration** next to your profile in the upper-right corner. <img src="https://mintcdn.com/moengage-user-guide/7jgjNiC47PDmtibB/images/moengage_6f68bb.png?fit=max&auto=format&n=7jgjNiC47PDmtibB&q=85&s=62c6466a299e66800c6f2ed1786c2006" width="2286" height="1018" data-path="images/moengage_6f68bb.png" />
    3. Click **Applications** > **Applications**. <img src="https://mintcdn.com/moengage-user-guide/NYCHSUAppO_GrSfM/images/moengage_6a1782.png?fit=max&auto=format&n=NYCHSUAppO_GrSfM&q=85&s=14dd0b1263b449c3e5446abcf3eb5440" width="2888" height="1342" data-path="images/moengage_6a1782.png" />
    4. On the Application page, click **Add app**. <img src="https://mintcdn.com/moengage-user-guide/0O_bXa3mWpWRhLiI/images/moengage_edf9eb.png?fit=max&auto=format&n=0O_bXa3mWpWRhLiI&q=85&s=09d4a17ca56d00fff94e05ef6a6e7ad4" width="2932" height="1108" data-path="images/moengage_edf9eb.png" /> The Find Applications page appears.
    5. In the **Search** box, type SAML, scroll through the page, and click **SAML Test Connector (IdP)**. <img src="https://mintcdn.com/moengage-user-guide/6Cv-o-foj_xuv48L/images/moengage_c2db41.png?fit=max&auto=format&n=6Cv-o-foj_xuv48L&q=85&s=2c44dbf6c527c8e68f341c0aa425ab31" width="2874" height="1364" data-path="images/moengage_c2db41.png" /> The Add SAML Test Connector (IdP) page appears.
    6. In the **Display Name** box, type the SAML name being tested. (Optional)
    7. Click **Save**. <img src="https://mintcdn.com/moengage-user-guide/bDzf7AaIU2Wu7s2U/images/moengage_024e1e.png?fit=max&auto=format&n=bDzf7AaIU2Wu7s2U&q=85&s=bdb7468e8c72122c4fbccb9c2549b957" width="2866" height="1358" data-path="images/moengage_024e1e.png" /> Your SAML is now successfully added, and the SAML Test Connector (IdP) page appears.
    8. Click **Configuration** on the left navigation menu. <img src="https://mintcdn.com/moengage-user-guide/zi8OFpJJZ8wcpIWO/images/moengage_2af881.png?fit=max&auto=format&n=zi8OFpJJZ8wcpIWO&q=85&s=82c9cf45446cacf244f5929e9704da90" width="2874" height="1368" data-path="images/moengage_2af881.png" />
    9. On the **Configure SSO** dialog box in the MoEngage dashboard, copy the **Audience, ACS (Consumer) URL Validator**, and **Single Logout Url**. <img src="https://mintcdn.com/moengage-user-guide/4venoFKsDzNYAMsx/images/moengage_99a095.png?fit=max&auto=format&n=4venoFKsDzNYAMsx&q=85&s=8089a433b2f533b276875da70bcac090" width="2308" height="1360" data-path="images/moengage_99a095.png" />
    10. In the **Application details** section, enter the following details:
        | Field                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | Required | Description                                                                                                                                                                                                              |
        | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
        | Audience                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | Yes      | This URL specifies the intended recipient of the SAML assertion.  Paste the audience copied from the MoEngage dashboard.                                                                                                 |
        | ACS (Consumer) URL Validator                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | Yes      | This URL adds an additional security to ensure MoEngage only accepts SAML assertions.  Paste the URL validator copied from the MoEngage dashboard.                                                                       |
        | ACS (Consumer) URL                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | Yes      | This URL receives and processes the SAML authentication data for MoEngage from Onelogin.  **Note**: Paste the **ACS (Consumer) URL Validator** you copied from the MoEngage dashboard in the **ACS (Consumer) URL** box. |
        | Single Logout URL                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | Yes      | This URL allows for single logout functionality.                                                                                                                                                                         |
        | <img src="https://mintcdn.com/moengage-user-guide/wO32kP8qzvGVyBFG/images/moengage_caf5be.png?fit=max&auto=format&n=wO32kP8qzvGVyBFG&q=85&s=b7ee8d2c72472777eb9551a3c0cda90a" width="2872" height="1354" data-path="images/moengage_caf5be.png" /> |          |                                                                                                                                                                                                                          |
    11. Click **Save**. Your SAML configuration is now successfully updated. <img src="https://mintcdn.com/moengage-user-guide/N4OwXnM8mFmK-SMM/images/moengage_d9255f.png?fit=max&auto=format&n=N4OwXnM8mFmK-SMM&q=85&s=c86392b9e361380d10bcd54dee7da067" width="2806" height="1366" data-path="images/moengage_d9255f.png" />
    12. In the upper-right corner, click the **More Actions** arrow and select **SAML Metadata**. <img src="https://mintcdn.com/moengage-user-guide/hUHrtlmw9hyYma5H/images/moengage_c08391.png?fit=max&auto=format&n=hUHrtlmw9hyYma5H&q=85&s=ddd1939761ffe6acf05932f183a94d87" width="2806" height="1336" data-path="images/moengage_c08391.png" />\
        The metadata will be downloaded in an XML file.
    13. Click **Upload** to upload the downloaded XML file on the **Configure SSO** dialog box in the MoEngage dashboard.
    14. By default, the **Update the same config for Test Environment** check box is selected. When it is selected, the configuration is applied to both the test and live environments. Clear the check box if you want the configuration to be applied only to the live environment.
    15. Click **Configure**. <img src="https://mintcdn.com/moengage-user-guide/vbW0L13jO4xtQMap/images/moengage_796ccd.png?fit=max&auto=format&n=vbW0L13jO4xtQMap&q=85&s=b79e3877c5530d48f8acb88e26bab93e" width="1762" height="1206" data-path="images/moengage_796ccd.png" /> The Alert pop-up window will appear, prompting you to review the instructions properly.
    16. Select the **Send email to the users of this workspace** check box to notify all users about your workspace's Single Sign-On (SSO) enablement.
    17. Click **Done**. <img src="https://mintcdn.com/moengage-user-guide/UOu66ZvIudsFME7I/images/moengage_3c648e.png?fit=max&auto=format&n=UOu66ZvIudsFME7I&q=85&s=52e390489f6ceef96ae62d118223bb81" width="2008" height="1006" data-path="images/moengage_3c648e.png" /> The SSO configuration is now successfully completed. You can see Onelogin SSO on the **Login** tab. <img src="https://mintcdn.com/moengage-user-guide/a6gDmhXi5PAv8cuv/images/moengage_54d4bd.png?fit=max&auto=format&n=a6gDmhXi5PAv8cuv&q=85&s=f11a2dbacfceee9ba79ca650f9933001" width="1992" height="1250" data-path="images/moengage_54d4bd.png" />
  </Tab>

  <Tab title="Configure Microsoft Azure SSO">
    To set up SSO with Azure, perform the following steps:

    1. Navigate to the **Azure Admin Console**.
    2. On the Azure services page, click **Microsoft Entra ID**. <img src="https://mintcdn.com/moengage-user-guide/WnxHNxVmb-EfNMzm/images/moengage_f8dae1.png?fit=max&auto=format&n=WnxHNxVmb-EfNMzm&q=85&s=c2644b45c8f337a275317b8255d24cc8" width="2878" height="1364" data-path="images/moengage_f8dae1.png" />
    3. On the Overview page, go to the left navigation menu and click **Manage** > **Enterprise** **applications**. <img src="https://mintcdn.com/moengage-user-guide/s2jfZa6amEeJ4PNc/images/moengage_a6d744.png?fit=max&auto=format&n=s2jfZa6amEeJ4PNc&q=85&s=55dbf0100c115b7223b567cc79313737" width="2544" height="1214" data-path="images/moengage_a6d744.png" />
    4. On the Enterprise applications | All applications page, click **+ New application**. <img src="https://mintcdn.com/moengage-user-guide/s2jfZa6amEeJ4PNc/images/moengage_a65fbd.png?fit=max&auto=format&n=s2jfZa6amEeJ4PNc&q=85&s=4449cfa23b64b9f1a34e421d958ec83a" width="2544" height="1268" data-path="images/moengage_a65fbd.png" />
    5. On the Browse Microsoft Entra Gallery page, in the search box, type **SAML Toolkit.**
    6. Click the **Microsoft Entra SAML Toolkit** tile and create the application. <img src="https://mintcdn.com/moengage-user-guide/m0UHvXd8pax8UuCU/images/moengage_4cbc0d.png?fit=max&auto=format&n=m0UHvXd8pax8UuCU&q=85&s=01a3fd2e3415df0e45f2090bea4d419d" width="2540" height="1272" data-path="images/moengage_4cbc0d.png" /> The created application is listed on the **Enterprise applications**| **All applications** page.
    7. In the **Search by application name or object ID** box, type the name of the application that you created and select the application. <img src="https://mintcdn.com/moengage-user-guide/oiUppy7Ie5QMgKGX/images/moengage_96d188.png?fit=max&auto=format&n=oiUppy7Ie5QMgKGX&q=85&s=c4732cf6af4bfae16ae4388d0174646a" width="2286" height="1236" data-path="images/moengage_96d188.png" />\
       Your created application appears. <img src="https://mintcdn.com/moengage-user-guide/uGNX_MpRdG3IdzJw/images/moengage_0d1f80.png?fit=max&auto=format&n=uGNX_MpRdG3IdzJw&q=85&s=b0de11244523400c59416da0489aa030" width="2544" height="1270" data-path="images/moengage_0d1f80.png" /> Now, you must configure SSO for the application you created.
    8. On your opened application page, go to the left navigation menu and click **Manage** > **Single sign-on**. <img src="https://mintcdn.com/moengage-user-guide/w6R2vb7TxqSd4fQE/images/moengage_348d7f.png?fit=max&auto=format&n=w6R2vb7TxqSd4fQE&q=85&s=be3761a53011168d49f2e927bb9fda70" alt="sso2.png" width="5088" height="2480" data-path="images/moengage_348d7f.png" /> The SAML-based Sign-On configuration page for your created application appears. <img src="https://mintcdn.com/moengage-user-guide/rDxK3ek_Jt3G54ss/images/moengage_7c45c0.png?fit=max&auto=format&n=rDxK3ek_Jt3G54ss&q=85&s=88b7cbb8c0d4f66aa00d26cf79961b49" width="2538" height="1244" data-path="images/moengage_7c45c0.png" />
    9. Move to the first step, **Basic SAML Configuration**, to define your metadata.
    10. In the **Basic SAML Configuration** section, click **Edit** in the upper-right corner. The **Basic SAML Configuration** pane appears on the right side. <img src="https://mintcdn.com/moengage-user-guide/a6gDmhXi5PAv8cuv/images/moengage_544830.png?fit=max&auto=format&n=a6gDmhXi5PAv8cuv&q=85&s=7aff0298d618e42870ae38c56ce90f53" width="2542" height="1246" data-path="images/moengage_544830.png" />
    11. On the **Configure SSO** dialog box in the MoEngage dashboard, copy the **Identifier (Entity ID)** and the **Reply URL (Assertion Consumer Service URL)**. **Note**: Copying the **Sign on URL** is optional and generally not recommended. <img src="https://mintcdn.com/moengage-user-guide/LNSaIrgVyFV18WvY/images/moengage_e68760.png?fit=max&auto=format&n=LNSaIrgVyFV18WvY&q=85&s=2954154e5ff39e43753fcc9f87a8b345" width="2298" height="1358" data-path="images/moengage_e68760.png" />
    12. In the **Basic SAML Configuration section**, enter the following details:
        | Field                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | Required                                | Description                                                                                                                                                    |
        | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- |
        | Identifier (Entity ID)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | Yes                                     | This URL allows MoEngage to verify authentication requests from Azure, ensuring secure and seamless logins.  Paste the ID copied from the MoEngage dashboard.  |
        | Reply URL (Assertion Consumer Service URL)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | Yes                                     | This URL receives and processes the SAML authentication data for MoEngage from Azure.  Paste the reply URL copied from the MoEngage dashboard.                 |
        | Sign on URL                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | Optional and generally not recommended. | This URL is the entry point from Azure that triggers the SAML SSO process to access MoEngage.  <br />Paste the sign-on URL copied from the MoEngage dashboard. |
        | <img src="https://mintcdn.com/moengage-user-guide/e_F7P_rJzpUjvM5l/images/moengage_7294e3.png?fit=max&auto=format&n=e_F7P_rJzpUjvM5l&q=85&s=76cac34515d7f13fa3f2d08a9dcd510e" width="2542" height="1246" data-path="images/moengage_7294e3.png" /> |                                         |                                                                                                                                                                |
    13. Click **Save**.
    14. Your SSO configuration has been successfully saved. To download the XML file, move to the third step, **SAML Certificates**.
    15. In the **SAMLCertificates** section, click **Download** adjacent to the **Federation Metadata XML**. <img src="https://mintcdn.com/moengage-user-guide/FL-P7uwjwPpxTJrP/images/moengage_9fa547.png?fit=max&auto=format&n=FL-P7uwjwPpxTJrP&q=85&s=c0e76b37663fc18d368bc8bd90624ce1" width="2540" height="1216" data-path="images/moengage_9fa547.png" /> The metadata will be downloaded in an XML file.
    16. Click **Upload**to upload the downloaded XML file on the **Configure SSO** dialog box in the MoEngage dashboard.
    17. By default, the **Update the same config for Test Environment** check box is selected. When it is selected, the configuration is applied to both the test and live environments. Clear the check box if you want the configuration to be applied only to the live environment.
    18. Click **Configure**.\
        <img src="https://mintcdn.com/moengage-user-guide/qldDXt06kEifTu5N/images/moengage_0e3ec5.png?fit=max&auto=format&n=qldDXt06kEifTu5N&q=85&s=e7867214b9f936d740efe3f68eb89e2a" width="1754" height="1192" data-path="images/moengage_0e3ec5.png" /> The Alert pop-up window will appear, prompting you to review the instructions properly.
    19. Select the **Send email to the users of this workspace** check box to notify all users about your workspace's Single Sign-On (SSO) enablement.
    20. Click **Done**. <img src="https://mintcdn.com/moengage-user-guide/UOu66ZvIudsFME7I/images/moengage_3c648e.png?fit=max&auto=format&n=UOu66ZvIudsFME7I&q=85&s=52e390489f6ceef96ae62d118223bb81" width="2008" height="1006" data-path="images/moengage_3c648e.png" /> The SSO configuration is now successfully completed. You can see the Azure SSO on the **Login** tab. <img src="https://mintcdn.com/moengage-user-guide/2bqJD8jHfFmU7a0n/images/moengage_623487.png?fit=max&auto=format&n=2bqJD8jHfFmU7a0n&q=85&s=ae5a95758c9b05e8734aea7b0e743417" width="2068" height="1226" data-path="images/moengage_623487.png" />
  </Tab>

  <Tab title="Configure Google Admin SSO">
    To set up SSO with Google Admin, perform the following steps:

    1. Navigate to the **Google Admin Console**.
    2. On the left navigation menu, click **Apps** > click **Web and mobile apps**. <img src="https://mintcdn.com/moengage-user-guide/_GuRgbivz3px0yNk/images/moengage_88be0c.png?fit=max&auto=format&n=_GuRgbivz3px0yNk&q=85&s=e1297b06f47cee8049ab2fe0d05cb110" width="2670" height="1422" data-path="images/moengage_88be0c.png" />
    3. Click the **Add app** arrow and click **Add custom SAML** **app**. <img src="https://mintcdn.com/moengage-user-guide/vbW0L13jO4xtQMap/images/moengage_783989.png?fit=max&auto=format&n=vbW0L13jO4xtQMap&q=85&s=fd61dcb748a4f69de2d63a50a8d4ba56" width="2822" height="1266" data-path="images/moengage_783989.png" /> You are taken to the first step, **App details**, to define your app.
    4. On the **App details** page, enter the following details:
       | Field       | Required | Description                                                                                                                                     |
       | ----------- | -------- | ----------------------------------------------------------------------------------------------------------------------------------------------- |
       | App name    | Yes      | Name of your  SAML application.                                                                                                                 |
       | Description | Yes      | Description of your SAML application configuration.                                                                                             |
       | Upload logo | optional | Upload an image file (typically PNG, JPG, or GIF) to serve as your application icon.  <br />**Note**: The image file must be smaller than 4 MB. |
           <img src="https://mintcdn.com/moengage-user-guide/8iz16AheqipjeI8D/images/moengage_1acbb7.png?fit=max&auto=format&n=8iz16AheqipjeI8D&q=85&s=b8ce5e87a42b51710dcf61f1307ff982" width="2818" height="1406" data-path="images/moengage_1acbb7.png" />
    5. Click **Continue**. You are taken to the second step, **Google Identity Provider details**.
    6. Under **Option 1: Download IdP metadata**, click **Download Metadata**.\
       The metadata will be downloaded in an XML file.
    7. Click **Continue**. <img src="https://mintcdn.com/moengage-user-guide/S6pB9ma3UT3V_5ck/images/moengage_b1cfb8.png?fit=max&auto=format&n=S6pB9ma3UT3V_5ck&q=85&s=e1e89d5ef7fb8c02c0e71066f102379a" width="2428" height="1428" data-path="images/moengage_b1cfb8.png" /> You are taken to the third step, **Service provider details**.
    8. On the **Configure SSO** dialog box in the MoEngage dashboard, copy the **ACS URL** and **Entity ID**. <img src="https://mintcdn.com/moengage-user-guide/UZ0L2gnMB7jFatNp/images/moengage_a9af29.png?fit=max&auto=format&n=UZ0L2gnMB7jFatNp&q=85&s=7769d3c3586ddc90d775bd2693fa771f" width="1762" height="1188" data-path="images/moengage_a9af29.png" />
    9. On the **Service provider details** page, enter the following details:
       | Field     | Required | Description                                                                                                                                     |
       | --------- | -------- | ----------------------------------------------------------------------------------------------------------------------------------------------- |
       | ACS URL   | Yes      | This URL receives and processes the SAML authentication data for MoEngage from Google Admin.  Paste the URL copied from the MoEngage dashboard. |
       | Entity ID | Yes      | A unique identifier for your application.  Paste the ID copied from the MoEngage dashboard.                                                     |
       | Start URL | Optional | Leave this blank.                                                                                                                               |
    10. Select the **Signed response** check box to sign the entire SAML response, which includes the assertion and other protocol-related information.
    11. In the **Name ID format** list, select *Email*.
    12. Click **Continue**. <img src="https://mintcdn.com/moengage-user-guide/z5wObluGBPTSzQMv/images/moengage_d80ce0.png?fit=max&auto=format&n=z5wObluGBPTSzQMv&q=85&s=b79762f6d75762d910374771aae3b432" width="2798" height="1348" data-path="images/moengage_d80ce0.png" /> You are taken to the fourth step, **Attribute mapping**. Here, you can map optional user attributes (for example, first name, last name, and email address).
    13. Click **Finish**. <img src="https://mintcdn.com/moengage-user-guide/4venoFKsDzNYAMsx/images/moengage_9883df.png?fit=max&auto=format&n=4venoFKsDzNYAMsx&q=85&s=63e047825bdd04041307e0d12cacd787" width="2808" height="1208" data-path="images/moengage_9883df.png" /> Your SAML settings are updated.
    14. On the **Configure SSO** dialog box in the MoEngage dashboard, click **Upload** to upload the XML file that you downloaded in step 6.
    15. By default, the **Update the same config for Test Environment** check box is selected. When it is selected, the configuration is applied to both the test and live environments. Clear the check box if you want the configuration to be applied only to the live environment.
    16. Click **Configure**. <img src="https://mintcdn.com/moengage-user-guide/w89gcvhxT1w_pzZQ/images/moengage_45acf5.png?fit=max&auto=format&n=w89gcvhxT1w_pzZQ&q=85&s=e1e8d8a24f35ec955b2bd1fcd676c825" width="1768" height="1188" data-path="images/moengage_45acf5.png" /> The Alert pop-up window will appear, prompting you to review the instructions properly.
    17. Select the **Send email to the users of this workspace** check box to notify all users about your workspace's Single Sign-On (SSO) enablement.
    18. Click **Done**. <img src="https://mintcdn.com/moengage-user-guide/UOu66ZvIudsFME7I/images/moengage_3c648e.png?fit=max&auto=format&n=UOu66ZvIudsFME7I&q=85&s=52e390489f6ceef96ae62d118223bb81" width="2008" height="1006" data-path="images/moengage_3c648e.png" /> The SSO configuration is now successfully completed. You can see Google SSO on the **Login** tab. <img src="https://mintcdn.com/moengage-user-guide/bf3rBsH0ybQ_mM3n/images/moengage_251775.png?fit=max&auto=format&n=bf3rBsH0ybQ_mM3n&q=85&s=fe170fbdd050da729966b04ded72e897" width="2068" height="1226" data-path="images/moengage_251775.png" />
  </Tab>

  <Tab title="Configure Other SSO">
    <Info>
      If you are using an IDP that is not listed above, you can select the *Other* option from the **Identity Provider** list.
    </Info>

    To set up SSO with the **Other** option, perform the following steps:

    1. Complete the necessary setup within your IdP admin console.
    2. Add the metadata values displayed on the **Configure SSO** dialog box in the MoEngage dashboard to the corresponding fields in your IdP admin console.
    3. Download and save the SAML metadata file generated by your IdP.
    4. To upload the XML file you downloaded in the **Configure SSO** section of the MoEngage dashboard, click **Upload**.
    5. By default, the **Update the same config for Test Environment** check box is selected. When it is selected, the configuration is applied to both the test and live environments. Clear the check box if you want the configuration to be applied only to the live environment.
    6. Click **Configure**. <img src="https://mintcdn.com/moengage-user-guide/vPfPLgXbaQgu3u5z/images/moengage_15ca33.png?fit=max&auto=format&n=vPfPLgXbaQgu3u5z&q=85&s=4db2266d1a8af15262e88f61eb523dbb" width="1752" height="1196" data-path="images/moengage_15ca33.png" /> The Alert pop-up window will appear, prompting you to review the instructions properly.
    7. Select the **Send email to the users of this workspace** check box.
    8. Click **Done**. <img src="https://mintcdn.com/moengage-user-guide/UOu66ZvIudsFME7I/images/moengage_3c648e.png?fit=max&auto=format&n=UOu66ZvIudsFME7I&q=85&s=52e390489f6ceef96ae62d118223bb81" width="2008" height="1006" data-path="images/moengage_3c648e.png" /> The SSO configuration is now successfully completed. <img src="https://mintcdn.com/moengage-user-guide/FbErsVdzNV9sOQk9/images/moengage_651f7e.png?fit=max&auto=format&n=FbErsVdzNV9sOQk9&q=85&s=29c45f935251eb7b1a8962172b27ec3d" width="2068" height="1226" data-path="images/moengage_651f7e.png" />
  </Tab>
</Tabs>

# FAQs

<Accordion title="Facing an issue while logging in?">
  <img src="https://mintcdn.com/moengage-user-guide/-3vSwXDB0-23wJct/images/moengage_b3cc73.png?fit=max&auto=format&n=-3vSwXDB0-23wJct&q=85&s=1014f722f46909dea1214dc5ff3d247e" alt="Screenshot_2019-10-16_at_2.55.10_PM.png" width="438" height="374" data-path="images/moengage_b3cc73.png" />

  ***Authentication Failed***

  This generally happens when the SAML authentication with the Identity Provider fails. Please contact your identity provider for details.

  ***Persistent Error***

  MoEngage supports the admin login using an email id - password combination. The Admin can go back to the Single Sign On screen (Go to settings > Security Settings) and disable SSO.
</Accordion>

<Accordion title="Facing an issue while uploading the config file?">
  ### &#x20; <img src="https://mintcdn.com/moengage-user-guide/plASHx0RUUpvhgYP/images/moengage_afbbc6.png?fit=max&auto=format&n=plASHx0RUUpvhgYP&q=85&s=a0c8624dcdedce91791fabdd6c467095" alt="Screenshot_2019-11-14_at_2.17.20_PM.png" width="1184" height="640" data-path="images/moengage_afbbc6.png" />

  This generally happens when the uploaded XML file is invalid. Try again with the correct XML file. If the issue persists, check with your identity provider.
</Accordion>

<Accordion title="Which identity providers are supported by MoEngage?">
  MoEngage supports all identity providers (IdPs) that support SAML 2.0
</Accordion>

<Accordion title="Can different identity providers be used for different workspaces?">
  Yes, you can configure different identity providers for different workspaces. For example, you can use Okta to configure SSO for one workspace and Google for another. You can also have different identity providers for test and live environments.
</Accordion>

<Accordion title="Which identity provider (in case of multiple IdPs) will the user be redirected to after logging in?">
  The user will be redirected to the IDP associated with the most recent workspace that they used before the last session ended.
</Accordion>

<Accordion title="Is there a test environment using which SSO implementation can be tested?">
  You can use the test environment to test the SSO setup and verify that everything works as desired. Once you have verified it on the test, you will need to set up SSO again on the live environment. On the other hand, SSO gets configured to the test environment automatically if you configure it first in the live environment.
</Accordion>

<Accordion title="What happens if the user exists in the identity provider’s directory but not in MoEngage?">
  The user will not be able to log in to MoEngage if the user is not a part of the workspace in which the SSO has been enabled.
</Accordion>

<Accordion title="What happens if the user exists in the identity provider’s directory but does not have access to the SSO workspace linked with MoEngage?">
  The user will see the Auth Status Failure error on the MoEngage Dashboard while being redirected back from the identity provider.
</Accordion>

<Accordion title="Who can enable/disable SSO for a workspace on MoEngage?">
  The SSO can only be enabled / disabled / edited by a user with access to the *Setup & Manage* permission under *Login Settings*.

  The user with the necessary permissions can go to *Settings -> Login -> Authentication,* select *Single Sign On (SSO) Only,* and perform the necessary action.

  <img src="https://mintcdn.com/moengage-user-guide/fu8EK_X1PiwOoTOd/images/moengage_ff589e.png?fit=max&auto=format&n=fu8EK_X1PiwOoTOd&q=85&s=9b9d9c9605e6dfe6a85f334f4d19dbd4" alt="" width="2278" height="1494" data-path="images/moengage_ff589e.png" />
</Accordion>

<Accordion title="What happens if the SSO is not enabled for one of the workspaces or if different identity providers have been used for different workspaces?">
  If SSO is not enabled for one of the workspaces or if different identity providers have been used for the workspaces, the user will need to re-authenticate while switching between them.
</Accordion>

<Accordion title="What happens if the user wants to seamlessly switch between different workspaces after enabling SSO?">
  To switch between different workspaces without re-authenticating seamlessly, the user will need to enforce SSO on all the workspaces with the same identity provider in both the Test and Live environments.
</Accordion>

<Accordion title="Can we configure SSO to allow a specific set of users to log in using SSO and others to log in with ID and Password?">
  Only the admins have the option to log in using their MoEngage credentials once SSO is enabled. All other users must log in through SSO.
</Accordion>

<Accordion title="When using Microsoft Azure, what should be the value of the User Principal Name (UPN) attribute?">
  UPN consists of a UPN prefix (the user account name) and a UPN suffix (a DNS domain name). The prefix is joined with the suffix using the "@" symbol. For example, "[someone@example.com](mailto:someone@example.com)". A UPN must be unique among all security principal objects within a directory. Read more about it [here](https://learn.microsoft.com/en-us/azure/active-directory/hybrid/connect/plan-connect-userprincipalname).
</Accordion>

<Accordion title="What are some of the common issues faced by the users?">
  Here are some of the common issues faced and their resolutions.

  | Error                        | Resolution                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
  | ---------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
  | *Incorrect Cluster URL*      | Ensure that the correct login URL (as per your data center) is used to log into your MoEngage Dashboard. For more information, refer to [Data Centers](/user-guide/data/key-concepts/data-centers-in-moengage).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
  | *Incorrect Name ID Format*   | The Name ID Format should be in the format mentioned below: *urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress*                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
  | *Missing Single Sign On URL* | The Single Sign On URL should be present with a valid value in the SAML metadata file.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
  | *NameIDFormat*               | `<NameIDFormat>`urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress`</NameIDFormat><NameIDFormat>`urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified`</NameIDFormat><NameIDFormat>`urn:oasis:names:tc:SAML:1.1:nameid-format:X509SubjectName`</NameIDFormat><NameIDFormat>`urn:oasis:names:tc:SAML:1.1:nameid-format:WindowsDomainQualifiedName`</NameIDFormat><NameIDFormat>`urn:oasis:names:tc:SAML:2.0:nameid-format:kerberos`</NameIDFormat><NameIDFormat>`urn:oasis:names:tc:SAML:2.0:nameid-format:entity`</NameIDFormat><NameIDFormat>`urn:oasis:names:tc:SAML:2.0:nameid-format:persistent`</NameIDFormat><NameIDFormat>`urn:oasis:names:tc:SAML:2.0:nameid-format:transient`</NameIDFormat>` |
</Accordion>

<Accordion title="Does two-factor authentication remain enabled even after enabling SSO authentication?">
  Yes, two-factor authentication remains enabled even after you enable SSO for a workspace.
</Accordion>
