Topic
Updating Organization-Level SSO Metadata in Everbridge Member Portal
Description
Organizations within the same Everbridge account can maintain separate Single Sign-On (SSO) configurations for the Member Portal. Each organization supports a single metadata file, allowing independent configuration rather than a shared account-level metadata file.
When an identity provider (IdP) issues a metadata update, the notification typically includes certificate expiration details, effective date and time of the update, a metadata file location (often a URL), implementation steps, and potential service impact if not applied.
This article outlines the process to update or replace the SSO metadata file at the organization level within the Everbridge Member Portal. Follow the applicable procedure depending on whether only the metadata file is being updated or a full reconfiguration is required.
Preparation
Notify impacted users of the planned SSO update, including timing and any expected access impact.
Ensure that break glass access is configured prior to making changes. This allows continued platform access if SSO is temporarily unavailable. For additional information, see this knowledge article: EBS: Single Sign-On (SSO) Break Glass Access in Everbridge Suite.
Backup Existing Configuration
- Select the appropriate organization from the Manager Portal.
- Navigate to Settings.
- Select Security.
- Select Single Sign-On for Member Portal.
- Capture the existing configuration details for reference.
- Select Download to save the current metadata file.
Update Identity Provider Metadata File Only
- Access the Manager Portal with organization administrator permissions.
- Navigate to Settings.
- Select Security.
- Select Single Sign-On for Member Portal.
- Select the Edit icon next to the current metadata file.
- Choose the new metadata XML file obtained from the IdP.
- Select Open.
- Select Save.
- Proceed to validation of the SSO configuration.
Full Reconfiguration of Member Portal SSO
- Access the Manager Portal with account administrator permissions.
- Navigate to Settings.
- Select Security.
- Select Single Sign-On for Member Portal.
- Select Remove to clear the existing configuration.
- Enter the SSO Name based on the backup.
- Enter the API Name, ensuring it matches the Entity ID and ACS values exactly.
- Upload the Identity Provider Metadata file.
- Select the appropriate Security Hash Algorithm.
- Select Save.
- Optional: Enable Mobile App access and enter the corresponding key phrase.
- Select Save again to generate the Everbridge metadata download option.
Validate SSO Configuration
Conduct validation by initiating login attempts through SSO.
If authentication fails:
- Capture error messages and screenshots.
- Restore the previous configuration using the saved backup and metadata file.
- Coordinate with the identity provider administrator to review configuration details.
- Open a case with Everbridge Technical Support and include:
- Error message
- Impacted user
- Username used
- Date and time of attempt
Download Metadata for Record Retention
After successful configuration, download the updated metadata file for record retention.
- Access the Manager Portal with account administrator permissions.
- Navigate to Settings.
- Select Security.
- Select Single Sign-On for Manager Portal.
- Select Download to save the metadata XML file.
Maintaining accurate records of SSO configurations supports auditability and simplifies future updates.
Related Articles
EBS: Troubleshooting Single Sign-On (SSO) in Everbridge Suite
EBS: Troubleshooting & Configuration Guide for Single Sign-On (SSO) - Main Page