Everbridge Single Sign-On (SSO)
Overview
Single Sign-On (SSO) is an authentication method that allows users to log in to multiple applications and websites with one set of credentials. When configured for use with Everbridge, SSO enables users to use their internal company credentials to log in to their respective Everbridge portals.
By using SSO, users can enter their login credentials once to be able to access several different applications (Service Providers) that are configured within their company's Identity Provider (IdP) application.
The Service Provider is the application that users are trying to access, while the Identity Provider (IdP) is the service that authenticates users and provides their identity information. So, when users log in to Everbridge using SSO, Everbridge relies on the IdP to verify their credentials.
You can create Single Sign-On settings for the Manager Portal, ManageBridge and a private Everbridge Member Portal using SAML (Security Assertion Markup Language) version 2.0. Note: SSO is not available for the public member portal since a public member portal does not require a login.
SSO is configured for the Manager Portal and ManageBridge at the Account level. SSO for the Everbridge Member Portal (private) can be configured at the Account level or at the Organization level. If SSO is configured at the Account level, all Organizations under that Account inherit the Account-level SSO configuration for their Member Portal. Configuring SSO at the Organization level allows you to define SSO for a specific Organization. If SSO is defined at the Account level, configurating SSO at the Organization level will override the Account-level SSO settings.
Each SSO configuration (Manager Portal, ManageBridge, and private Member Portal) is differentiated by a Name and an API name. API names must be unique across all Everbridge Accounts and Organizations. Everbridge uses this attribute to generate an Everbridge Login URL.
When SSO is configured, only contacts with an SSO User ID in their record can log in using SSO. This allows you to control SSO access by assigning SSO User IDs only to specific contact records. Enabling SSO does not automatically remove existing Everbridge credentials, but provides an additional login method for those contacts with an SSO User ID.
SSO manages user authentication only. It does not, by itself, create (provision) or authorize Everbridge user accounts. Enabling SSO does not guarantee that an Everbridge account will be created automatically when a user first attempts to sign in; user provisioning and authorization must still follow your standard Everbridge user and contact management processes.
Getting Started
SSO for Everbridge is self-serve for customers. To configure SSO, follow the Everbridge SSO prerequisites, overview, and configuration guides, making sure to select the correct deployment (EU versus .NET). You should also review the Everbridge SSO break-glass access guidance, and, if you are using Microsoft Azure Active Directory as your IdP, the Everbridge Azure AD tutorial for step-by-step configuration details.
EBS: Single Sign-On (SSO) Terms and Definitions
EBS: Troubleshooting & Configuration Guide for Single Sign-On (SSO) - Main Page