This is a master checklist for SAML SSO customer intake. The General section applies to any Identity Provider. Below it, IdP specific questions are provided.
General (any SAML 2.0 Identity Provider)
Attributes & Identifiers
- The complete list of email domains your staff use to sign in — including any subdomains, legacy domains, or department-specific domains. We route users to your IdP by domain, so any domain left off this list will fail to sign in via SSO.
- Which SAML attribute carries the user's email address, and is it marked verified in your directory? Are
given_nameandfamily_nameincluded in the assertion? - Is the NameID persistent per user, and in what format —
persistent,emailAddress,unspecified, ortransient? A transient NameID changes on every login, which would prevent us from reliably linking an account to a person. - Do any staff have more than one email address on file (e.g., a directory address plus an alias)? Which one will your IdP assert?
Protocol & Trust
- The URL for your IdP's SAML metadata (preferred), or a static metadata file if a URL isn't available.
- Do you require signed AuthnRequests and/or encrypted assertions?
- Who owns certificate rotation on your side, on what cadence, and how much advance notice should we expect?
Policy
- Does your IdP enforce MFA for this application, and if so, with which factors?
- Are there any access or sign-on policies — IP allowlists, device-compliance requirements, conditional or adaptive access rules — that could block our connection?
Logistics
- Can you provide a test account for validation prior to go-live?
- Do you plan on connecting a non-production environment to Edvisorly, or only production?
- Who is the IdP administrator we should work with directly, and what's their typical change window or freeze calendar?
IdP-Specific: Microsoft Entra ID
- Which Microsoft Entra ID edition are you using — Free, P1, or P2? (Relevant because group-based access control and Conditional Access require P1/P2.)
- Will you be publishing an app tile for Eddy in My Apps? If so, we'll need it configured in Linked SSO mode pointing to
https://app.edvisorly.com/api/auth/login, rather than as an SSO-initiated app. - Which Entra security groups should control access to Eddy, and what are their object IDs? Which group represents your full advising staff?
Comments
0 comments
Article is closed for comments.