Acquia single sign-on (SSO) provides a unified single sign-on experience across Acquia ecosystem. With Acquia SSO, users authenticate with their own identity provider credentials. After configuration, Acquia SSO requires users with verified email domains to authenticate through their identity provider instead of standard Acquia ID credentials.
Acquia SSO supports common enterprise authentication flow through Security Assertion Markup Language 2.0 for secure identity exchange. It provides enterprises with flexibility to initiate log in sessions.
Service Provider-Initiated Flow: Users move directly to Cloud Platform and enter a corporate email address. Acquia redirects users to the organizational identity provider for authentication.
To enable Acquia SSO, an organization administrator must perform these steps. This configuration is managed at the subscription level and applies company-wide to all members with the configured email domain.
Acquia SSO is mandatory for all users with a configured domain.
Employees: The system routes employees with the configured corporate domain to the corporate identity provider for authentication. Acquia SSO is mandatory for configured domains. Users cannot opt out.
Partners and Consultants: If external users require access through the corporate identity provider, the IT team must provision them with email addresses from the configured corporate domain. Alternatively, external users can access Acquia with Acquia ID credentials after they receive approval from organization administrators. These users authenticate through one of the following methods:
Organization administrators are responsible for these actions:
Pre-Configuration Steps:
Locate existing user accounts that use email sub-addresses, such as [email protected].
Re-provision these users in your corporate identity provider with distinct, domain-recognized email addresses
If this content did not answer your questions, try searching or contacting our support team for further assistance.
Pre-Configuration Steps:
Locate existing user accounts that use email sub-addresses, such as [email protected].
Re-provision these users in your corporate identity provider with distinct, domain-recognized email addresses
If this content did not answer your questions, try searching or contacting our support team for further assistance.