To add a domain:
Select the Domains tab.
Select Add Domain.
In Domain Name, enter the corporate email domain.
Click Add.
The domain appears in the list with an Unverified status.
Click the Verify link next to the domain name.
Copy the TXT record (the string starting with acquia-domain-verification=) and add it to your DNS settings.
Click the Refresh icon in the list to update the status to Verified.
To remove a domain:
Locate the verified or unverified domain in the Domains list.
Select the Delete icon.
Review the confirmation dialog box.
Select Remove.
Review the following information to resolve domain errors:
Domain already exists: You cannot add a domain already associated with another IdP.
Verification Failed: Ensure that the TXT record is correctly added to the DNS because DNS propagation can take up to 48 hours.
Invalid Format: Ensure that the domain name does not include https:// or sub-pages.
To add an IdP:
Select the Identity Providers tab.
Select Add Identity Provider.
Complete the following fields:
Label: A label for your reference, such as Main Okta.
Domains: The verified domains that the IdP supports.
Entity ID: The unique ID that the IdP provides.
SSO URL: The sign-on URL that the IdP provides.
Public Certificate: Paste the X.509 certificate in PEM format.
Select Submit.
Click Enable or Disable.
The system displays the Enable or Disable dialog box.
The system displays the success notification, and the status changes to Enabled or Disabled.
After you add and enable the IdP, you must map SAML attributes to identify users correctly in Acquia. The IdP must send the following three attributes with the exact names specified, if the attribute names do not match, Acquia cannot create or update user profiles correctly:
| Attribute name | Description |
|---|---|
firstName | The first name of the user. |
lastName | The last name of the user. |
email | The primary email address of the user. |
The exact steps to map these attributes depend on the IdP. For more information, refer to Configure Microsoft Entra ID as an Identity Provider and Configure Google Workspace as an Identity Provider.
To edit or delete an IdP:
To edit: Select the Edit icon next to the provider, update the certificate or URLs, and select Save.
To delete: Select the Delete icon. You cannot delete an IdP if verified domains remain attached to it. You must remove the domains first.
Review the following information to resolve IdP errors:
Field is required: You must complete all fields including Name, Entity ID, SSO URL, and Certificate before you submit.
Invalid Certificate: The certificate must be a valid PEM file. Ensure that no extra spaces exist and the ---BEGIN CERTIFICATE--- headers are present.
SSO Connection Failed: Ensure that the ACS URL that Acquia provides is correctly entered in the IdP configuration.
Domain verification serves as the security foundation of the Acquia SSO workflow
Acquia SSO uses the domain portion of a user email address, such as [email protected], as the core routing mechanism
Without a secure domain claim step, technical proof of ownership does not existyourcompany.com as a custom domain in an unauthorized Acquia account
To prevent domain hijacking, Acquia requires the IT administration team to add a unique Domain Name System (DNS) TXT record to the public routing configuration of the domain
If this content did not answer your questions, try searching or contacting our support team for further assistance.
If this content did not answer your questions, try searching or contacting our support team for further assistance.