Topic
Uploading a new metadata file into the Single Sign-On (SSO) settings at the account level for the Everbridge Member Portal.
Description
After acquiring a new certificate or when Identity Provider (IdP) system settings change, follow the steps below.
Prepare the Organization
Before making changes, communicate to contacts that SSO is scheduled for reconfiguration.
Backup the Existing Configuration
- Log in to the Manager Portal as an Account Administrator.
- Select Settings from the top menu bar.
- Select Security from the menu on the left.
- Select Single Sign-On for Member Portal from the sub-menu.
- Capture the existing configuration by taking screenshots or copying the information into a text file.
- Click Download at the bottom of the page, to the right of each Member Portal configuration, to download the existing metadata files.
Update Only the Identity Provider Metadata File
- Log in to the Manager Portal as an Account Administrator.
- Select Settings from the top menu bar.
- Select Security from the menu on the left.
- Select Single Sign-On for Member Portal from the sub-menu.
- Select the Edit icon to the right of the current metadata file name.
- Select the new metadata file from local files.
- Select Open.
- Select Save.
- Proceed to testing the SSO configuration.
Reconfigure Member Portal SSO Settings
- Log in to the Manager Portal as an Account Administrator.
- Select Settings from the top menu bar.
- Select Security from the menu on the left.
- Select Single Sign-On for Member Portal from the sub-menu.
- Select Remove to clear the existing configuration.
- Using the backup, re-enter the Name for the SSO instance.
- Using the backup, re-enter the API Name. The API name must exactly match the Entity ID and Reply URLs.
- Upload the Identity Provider Metadata file by selecting Choose File.
- Select the appropriate option for the Security Hash Algorithm.
- Select the appropriate option for the SAML Identity Location.
- Select the appropriate option for the Service Provider Initiated Request Binding.
- Select the appropriate option for the Single Logout Redirector.
- Select Save.
- Select the checkbox for Member Portal to enable SSO access.
- Optional: Select the checkbox for Mobile App to enable SSO access for the Everbridge Mobile App. Populate the Mobile App Key Phrase using the backup configuration.
- Select Save again to enable the option to Download the metadata file from Everbridge. When the Download option appears next to the organization name, reconfiguration is complete.
Test the New SSO Configuration
Request a small group of contacts to attempt login using SSO. If login fails:
- Capture screenshots and exact error messages.
- Restore the previous configuration by uploading the prior metadata and re-entering the saved settings from the backup step.
- Contact the IdP administrator to determine whether an issue exists on the IdP side.
- Contact Everbridge Support and provide the error message, impacted user, username used during login, and the date and time of the failed attempt.
Download XML for Record Keeping
If reconfiguration is successful, download the XML file used to create the new SSO configuration for record keeping by following the steps below:
- Log in to the Manager Portal as an Account Administrator.
- Select Settings from the top menu bar.
- Select Security from the menu on the left.
- Select Single Sign-On for Member Portal from the sub-menu.
- Select Download at the bottom of the configuration page.
Related Articles
EBS: Troubleshooting & Configuration Guide for Single Sign-On (SSO) - Main Page
EBS: Troubleshooting Single Sign-On (SSO) in Everbridge Suite