{"id":1509,"date":"2023-11-21T07:29:33","date_gmt":"2023-11-21T07:29:33","guid":{"rendered":"https:\/\/support.alfaview.com\/?page_id=1509"},"modified":"2026-02-04T09:22:21","modified_gmt":"2026-02-04T09:22:21","slug":"single-sign-on","status":"publish","type":"page","link":"https:\/\/support.alfaview.com\/en\/miscellaneous\/for-it-administrators\/single-sign-on\/","title":{"rendered":"Single Sign-On"},"content":{"rendered":"\n<p>With single sign-on you can use your existing identity provider to log in to alfaview.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/support.alfaview.com\/en\/miscellaneous\/for-it-administrators\/single-sign-on\/#requirements-and-limitations\">Requirements and Limitations<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/support.alfaview.com\/en\/miscellaneous\/for-it-administrators\/single-sign-on\/#setup-process\">Setup Process<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/support.alfaview.com\/en\/miscellaneous\/for-it-administrators\/single-sign-on\/#manage-groups-for-single-sign-on-authentication-users\">Manage groups for single sign-on authentication users<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"requirements-and-limitations\">Requirements and Limitations<a href=\"#requirements-and-limitations\" class=\"av-heading-anchor\"><i class=\"bi bi-link\"><\/i><\/a><\/h2>\n\n\n\n<p>In order to setup single sign-on you have to have a working identity provider. It needs to comply to the either of the following standards:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>OpenID Connect<\/li>\n\n\n\n<li>SAML V2.0<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"required-information\">Required Information<a href=\"https:\/\/support.alfaview.com\/en\/administration\/single-sign-on\/requirements-and-limitations\/#required-information\"><\/a><a href=\"#required-information\" class=\"av-heading-anchor\"><i class=\"bi bi-link\"><\/i><\/a><\/h3>\n\n\n\n<p>To configure our alfaview service provider we need the following information from you:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>the endpoint of your identity provider (e. g.&nbsp;<code>https:\/\/idp.example.com\/redirect<\/code>)\n<ul class=\"wp-block-list\">\n<li>if available: test accounts and an additional testing identity provider endpoint<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>if you have a SAML-based identity provider: the URL to your identity provider&#8217;s metadata XML file<\/li>\n\n\n\n<li>the identity claims or attribute mapping of your identity provider\u2019s SAML\/OIDC response\n<ul class=\"wp-block-list\">\n<li>required: user\u2019s first name, last name and display name<\/li>\n\n\n\n<li>optional: user group attribute if you want to use&nbsp;<a href=\"\/en\/administration\/single-sign-on\/manage-groups\/\">group based permission management<\/a>&nbsp;in alfaview<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>your desired login domain from where your users will start the single sign-on process (example:&nbsp;<code>my-company.alfaview.com<\/code>)<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"limitations\">Limitations<a href=\"#limitations\" class=\"av-heading-anchor\"><i class=\"bi bi-link\"><\/i><\/a><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Your identity provider\u2019s SAML XML signature needs to be signed using the SHA256 algorithm. If you have no information about the signing algorithm used, we can try to help you finding it out.<\/li>\n\n\n\n<li>We do not support identity provider initiated SAML V2.0. But we can provide a start link that initiates the alfaview login by redirecting to your identity provider\u2019s login page<\/li>\n\n\n\n<li>The login domain will be hosted by alfaview.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"compatible-identity-providers\">Compatible Identity Providers<a href=\"https:\/\/support.alfaview.com\/en\/administration\/single-sign-on\/requirements-and-limitations\/#compatible-identity-providers\"><\/a><a href=\"#compatible-identity-providers\" class=\"av-heading-anchor\"><i class=\"bi bi-link\"><\/i><\/a><\/h3>\n\n\n\n<p>Here is a list of identity providers that were successfully configured and are proven to work with alfaview:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>GitLab \u2013 based on OpenID Connect<\/li>\n\n\n\n<li>Google Work \u2013 based on SAML V2.0<\/li>\n\n\n\n<li>Shibboleth \u2013 based on SAML V2.0<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"setup-process\">Setup Process<a href=\"#setup-process\" class=\"av-heading-anchor\"><i class=\"bi bi-link\"><\/i><\/a><\/h2>\n\n\n\n<p>If you are interested in using Single Sign-On, use our <a href=\"https:\/\/alfaview.com\/en\/contact\/\" data-type=\"link\" data-id=\"https:\/\/alfaview.com\/en\/contact\/\">contact form<\/a> to get in touch with us.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/alfaview.com\/en\/contact\/\">Contact form<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"manage-groups-for-single-sign-on-authentication-users\">Manage groups for single sign-on authentication users<a href=\"#manage-groups-for-single-sign-on-authentication-users\" class=\"av-heading-anchor\"><i class=\"bi bi-link\"><\/i><\/a><\/h2>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<p>Users that use single sign-on (SSO) to authenticate with alfaview can be assigned to groups in the external Identity provider (IdP). These groups can be mapped to groups with specific permissions in alfaview and can be assigned to alfaview rooms and departments. This helps in managing large numbers of users in alfaview.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:33.33%\"><div class=\"wp-block-image\">\n<figure class=\"alignright size-full\"><a href=\"https:\/\/support.alfaview.com\/wp-content\/uploads\/2025\/11\/alfaview_sso_manage-groups_en.png\"><img loading=\"lazy\" decoding=\"async\" width=\"780\" height=\"353\" src=\"https:\/\/support.alfaview.com\/wp-content\/uploads\/2025\/11\/alfaview_sso_manage-groups_en.png\" alt=\"Screenshot of the Manage groups tab in the Company management\" class=\"wp-image-10203\" srcset=\"https:\/\/support.alfaview.com\/wp-content\/uploads\/2025\/11\/alfaview_sso_manage-groups_en.png 780w, https:\/\/support.alfaview.com\/wp-content\/uploads\/2025\/11\/alfaview_sso_manage-groups_en-300x136.png 300w, https:\/\/support.alfaview.com\/wp-content\/uploads\/2025\/11\/alfaview_sso_manage-groups_en-768x348.png 768w\" sizes=\"auto, (max-width: 780px) 100vw, 780px\" \/><\/a><figcaption class=\"wp-element-caption\">Manage groups<\/figcaption><\/figure>\n<\/div><\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-alfaview-callout\">\n<p>To configure this setting, you will need the permission to&nbsp;<strong>manage company settings<\/strong>. Additionally, the company needs to have its own custom subdomain to access this feature.<\/p>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"creating-groups\">Creating groups<a href=\"https:\/\/support.alfaview.com\/en\/administration\/single-sign-on\/manage-groups\/#creating-groups\"><\/a><a href=\"#creating-groups\" class=\"av-heading-anchor\"><i class=\"bi bi-link\"><\/i><\/a><\/h3>\n\n\n\n<p>In the&nbsp;<a href=\"\/en\/administration\/general\/adminstration-interface\/\">administration interface<\/a>, navigate to account management &gt; Manage groups. Click <button class=\"av-button av-button--primary\">Add<\/button> and fill in the required fields.<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<ul class=\"wp-block-list\">\n<li><strong>Name:<\/strong>&nbsp;A name that will only be visible in this interface, an easy way to assign meaning to a group. (Example: Students, Teachers, etc)<\/li>\n\n\n\n<li><strong>External ID:<\/strong>&nbsp;A unique ID that is managed by the IdP and will be sent on each login. It must exactly match the group from the IdP response and cannot be empty. Also this value is unique: no two alfaview groups can have the same external ID.<\/li>\n\n\n\n<li><strong>Access Level:<\/strong> Decide whether and what type of profiles should be created for the group.\n<ul class=\"wp-block-list\">\n<li><strong>No user profiles:<\/strong> Group participants can join rooms but do not have their own profile.<\/li>\n\n\n\n<li><strong>Create user profiles:<\/strong> Participants receive their own user profile so that individual permissions can be assigned.<\/li>\n\n\n\n<li><strong>Administration Page Access:<\/strong> Participants receive a user profile and access to the alfaview administration interface.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Permissions:<\/strong>&nbsp;The selected permissions will be granted to all users belonging to this group.<\/li>\n<\/ul>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:33.33%\"><div class=\"wp-block-image\">\n<figure class=\"alignright size-full\"><a href=\"https:\/\/support.alfaview.com\/wp-content\/uploads\/2025\/11\/alfaview_sso_create-group_en.png\"><img loading=\"lazy\" decoding=\"async\" width=\"400\" height=\"593\" src=\"https:\/\/support.alfaview.com\/wp-content\/uploads\/2025\/11\/alfaview_sso_create-group_en.png\" alt=\"Screenshot of the Create group window with all setting options\" class=\"wp-image-10211\" srcset=\"https:\/\/support.alfaview.com\/wp-content\/uploads\/2025\/11\/alfaview_sso_create-group_en.png 400w, https:\/\/support.alfaview.com\/wp-content\/uploads\/2025\/11\/alfaview_sso_create-group_en-202x300.png 202w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><\/a><figcaption class=\"wp-element-caption\">Create group<\/figcaption><\/figure>\n<\/div><\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-alfaview-callout\">\n<p>These permissions are&nbsp;<strong>always granted globally<\/strong>&nbsp;and cannot be restricted to a room or a department.<\/p>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"editing-groups\">Editing groups<a href=\"https:\/\/support.alfaview.com\/en\/administration\/single-sign-on\/manage-groups\/#editing-groups\"><\/a><a href=\"#editing-groups\" class=\"av-heading-anchor\"><i class=\"bi bi-link\"><\/i><\/a><\/h3>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<p>Existing groups can be edited via the group list on the main page. Click the triple dot menu for the related group, and select&nbsp;<strong>Edit<\/strong>. All options that are available in the Add dialog are also available in this dialog.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"deleting-groups\">Deleting groups<a href=\"https:\/\/support.alfaview.com\/en\/administration\/single-sign-on\/manage-groups\/#deleting-groups\"><\/a><a href=\"#deleting-groups\" class=\"av-heading-anchor\"><i class=\"bi bi-link\"><\/i><\/a><\/h3>\n\n\n\n<p>Existing groups can be deleted via the group list in the main page. Click the triple dot menu of the related group, and select&nbsp;<strong>Delete<\/strong>. A confirmation dialog will be shown. The delete action cannot be reverted, and the group must be recreated from start if needed.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:33.33%\"><div class=\"wp-block-image\">\n<figure class=\"alignright size-full\"><a href=\"https:\/\/support.alfaview.com\/wp-content\/uploads\/2025\/11\/alfaview_sso_edit-group_en.png\"><img loading=\"lazy\" decoding=\"async\" width=\"400\" height=\"593\" src=\"https:\/\/support.alfaview.com\/wp-content\/uploads\/2025\/11\/alfaview_sso_edit-group_en.png\" alt=\"Screenshot of the Edit group window with all setting options\" class=\"wp-image-10206\" srcset=\"https:\/\/support.alfaview.com\/wp-content\/uploads\/2025\/11\/alfaview_sso_edit-group_en.png 400w, https:\/\/support.alfaview.com\/wp-content\/uploads\/2025\/11\/alfaview_sso_edit-group_en-202x300.png 202w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><\/a><figcaption class=\"wp-element-caption\">Edit group<\/figcaption><\/figure>\n<\/div><\/div>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"assigning-groups-to-departments\">Assigning groups to departments<a href=\"https:\/\/support.alfaview.com\/en\/administration\/single-sign-on\/manage-groups\/#assigning-groups-to-departments\"><\/a><a href=\"#assigning-groups-to-departments\" class=\"av-heading-anchor\"><i class=\"bi bi-link\"><\/i><\/a><\/h3>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<p>Existing groups can be assigned to departments via the group list on the main page.<br>Click the <button class=\"av-button av-button--primary\">Assign<\/button> button of the related group. The assign dialog will be displayed.<br>All existing assignments can be edited or deleted on this page.<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:33.33%\"><div class=\"wp-block-image\">\n<figure class=\"alignright size-full\"><a href=\"https:\/\/support.alfaview.com\/wp-content\/uploads\/2025\/11\/alfaview_sso_assign-group_en.png\"><img loading=\"lazy\" decoding=\"async\" width=\"400\" height=\"170\" src=\"https:\/\/support.alfaview.com\/wp-content\/uploads\/2025\/11\/alfaview_sso_assign-group_en.png\" alt=\"Screenshot of the Assign group to departments window with all setting options\" class=\"wp-image-10208\" srcset=\"https:\/\/support.alfaview.com\/wp-content\/uploads\/2025\/11\/alfaview_sso_assign-group_en.png 400w, https:\/\/support.alfaview.com\/wp-content\/uploads\/2025\/11\/alfaview_sso_assign-group_en-300x128.png 300w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><\/a><figcaption class=\"wp-element-caption\">Assign group<\/figcaption><\/figure>\n<\/div><\/div>\n<\/div>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>To assign:<\/strong>&nbsp;Select a department from the dropdown list, select the permission level for this department and click <button class=\"av-button av-button--primary\">Add to department<\/button>.<\/li>\n\n\n\n<li><strong>To unassign:<\/strong>&nbsp;Click the trashcan icon for the related department.<\/li>\n\n\n\n<li><strong>To edit permission level:<\/strong>&nbsp;Click the dropdown for the related department and select a new permission.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>With single sign-on you can use your existing identity provider to log in to alfaview. Requirements and Limitations Setup Process Manage groups for single sign-on authentication users Requirements and Limitations In order to setup single [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":0,"parent":4549,"menu_order":10,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-1509","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/support.alfaview.com\/en\/wp-json\/wp\/v2\/pages\/1509","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/support.alfaview.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/support.alfaview.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/support.alfaview.com\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/support.alfaview.com\/en\/wp-json\/wp\/v2\/comments?post=1509"}],"version-history":[{"count":4,"href":"https:\/\/support.alfaview.com\/en\/wp-json\/wp\/v2\/pages\/1509\/revisions"}],"predecessor-version":[{"id":10490,"href":"https:\/\/support.alfaview.com\/en\/wp-json\/wp\/v2\/pages\/1509\/revisions\/10490"}],"up":[{"embeddable":true,"href":"https:\/\/support.alfaview.com\/en\/wp-json\/wp\/v2\/pages\/4549"}],"wp:attachment":[{"href":"https:\/\/support.alfaview.com\/en\/wp-json\/wp\/v2\/media?parent=1509"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}