Skip to main content

How to create a new SSO configuration

Create and configure a new SAML SSO integration.

H
Written by Harriet Christie

Summary

MirrorWeb Insight supports Single Sign-On (SSO) via SAML, configured from the SSO page in the Management module. You can set up a configuration using a provider template for Azure or Okta, or a generic SAML configuration. Each organisation supports a single SAML configuration; if one already exists you are returned to the SSO page to edit it instead.

Note: This article overlaps with the migrated "Setting up SSO" article and with How to configure SSO / SAML, which describes editing an existing configuration. They describe the same SSO feature.

Prerequisites

  • Login credentials for MirrorWeb Insight

  • Admin access to the organisation

  • Configuration details from your identity provider (for example Azure, Okta, or another SAML-compatible provider)

Step-by-Step Instructions

Step 1: Open the SSO page

In the Management sidebar, click SSO. If no SAML configuration exists yet, the page shows "No SAML config found" with a New button.

The SSO page with the No SAML config found state and the New button

Step 2: Start a new configuration

Click New to open the SSO Configuration page. Under "Select a provider", choose one of the provider cards: Azure, Okta, or generic.

The Select a provider step showing the Azure, Okta, and generic cards

Step 3: Enter your domain

After selecting a provider, the setup form opens (titled "Set up [provider] SSO"). In the Domain field, enter your organisation's domain name. The form displays the Reply URL (Assertion Consumer Service URL) and MirrorWeb's service provider identifier (shown as Identifier (Entity ID) for the generic provider, or Audience for Azure and Okta), each with a Copy button. Use these values to configure MirrorWeb as a service provider in your identity provider.

The provider setup form showing the Domain field, Reply URL, and Identifier values

Step 4: Enter the SAML details from your provider

Complete the remaining fields using the information from your identity provider:

  • Single sign-on URL (the SSO URL from your provider; labelled Login URL for Azure)

  • Issuer (for the generic and Okta providers)

  • Metadata Type — select HTTP or Stored XML. If HTTP, enter the Metadata URL; if Stored XML, paste the Metadata XML.

For the generic provider, a Show advanced option reveals additional fields: Public certificate, Certificate, Key, Entity ID, and SSO Service Location.

The SAML details section with the single sign-on URL, issuer, and metadata type fields

Step 5: Create the configuration

Click Create. If there is a problem with the configuration, an error toast appears asking you to check the form and try again, with a link to contact support at support@mirrorweb.com.

The completed SSO configuration form with the Create button

Notes

  • Each organisation supports a single SAML configuration. If a configuration already exists, opening New redirects you to the SSO page to edit the existing configuration.

  • The Reply URL is constructed from the domain you enter, so it updates as you type the domain.

  • For Azure and Okta, the form shows an information banner noting that you complete the second section of the form using the information provided by your identity provider.

  • After creating the configuration, edit and activate it from the SSO page. See How to configure SSO / SAML.

Did this answer your question?