Change identity providers and renew SSO certificates¶
To switch identity providers (IdPs) or renew an IdP signing certificate, upload new IdP metadata. Do this when your company moves to a new IdP, or before your IdP's signing certificate expires, so members can keep signing in with SSO. For first-time setup, see Set up single sign-on.
Applies to¶
- Jump Desktop for Teams Enterprise plan.
- Team administrators.
Before you start¶
Make sure you can still sign in if the new metadata doesn't work.
- In the Teams dashboard, open your team and click Security.
- In Team Single Sign On, clear Require SSO for 'team name' team and click Don't Require SSO. While SSO is required, members who have linked SSO can't sign in with a password.
- If a verified domain has Require SSO Login turned on, turn it off. See Verify your domain.
- In the sidebar, click Security (your account's page, not the team's). If you see Set Your Password, set one. (Change Your Password means you already have one.)
- If your account uses two-factor authentication, keep your authenticator app or backup codes at hand.
- Save a copy of your current IdP metadata XML file.
Upload the new metadata¶
- In your IdP, do one of the following:
- New provider: create a SAML app using the ACS URL and Entity ID from Manage SAML SSO. These don't change when you switch providers. Keep the old IdP app until testing passes. For per-provider steps, see Set up single sign-on.
- Expiring certificate: add the new signing certificate, and activate it before the old one expires.
- Download the IdP metadata XML file.
- On your team's Security page, click Manage SAML SSO.
- Click Upload IDP Metadata and choose the XML file. You'll see SAML IDP metadata updated.
Keep this browser window signed in until you've tested the change.
Members keep their Jump Desktop accounts. Before members rely on the new provider, confirm that someone who already signed in with the old provider can sign in with the new one (see Test the change). Contact Jump Desktop support if they can't.
Renew a certificate without downtime¶
Jump Desktop accepts any signing certificate listed in the uploaded metadata and rejects expired certificates. If your IdP can publish metadata with both the old and new certificates, upload it before switching the IdP to the new certificate, and before the old certificate expires.
Test the change¶
- Open a private (incognito) browser window and go to app.jumpdesktop.com.
- Click Sign in with SSO, enter your company name or email, and sign in through your IdP.
- New provider: repeat with another member who signed in with SSO before the switch. Test with them before requiring SSO again.
If sign-in fails, revert in the original window. If you were signed out, sign in with your email and password.
- New provider: upload the metadata file you saved.
- Certificate renewal: switch your IdP back to the old certificate and upload the saved metadata, or fix the new metadata and upload it again. Re-uploading the old metadata alone doesn't help.
Finish¶
After your members have signed in successfully, select Require SSO for 'team name' team again and turn any domain Require SSO Login settings back on.