Skip to content

Set up single sign-on

Single sign-on (SSO) lets team members sign in to Jump Desktop with their company account from your SAML 2.0 identity provider (IdP), such as Okta, Microsoft Entra ID, or Google Workspace. Administrators can then require SSO for every member. Use it to make everyone on the team sign in with company credentials, and as the base for domain verification and SCIM provisioning.

Applies to

  • A paid Jump Desktop for Teams Enterprise plan. Trials can't set up SSO.
  • Team administrators.
  • An identity provider (IdP) that supports SAML 2.0.

1. Create the SSO connection

  1. In the Teams dashboard, open your team and click Security.
  2. In Team Single Sign On, click Setup SAML SSO, then Next.
  3. Enter an SSO Company Name: 4 to 32 lowercase letters and numbers. Users enter this name when they sign in with SSO. Click Next.
  4. Click Create. You upload the IdP metadata in step 3.
  5. Click Manage SAML SSO and copy the ACS URL and Entity ID.

2. Configure your identity provider

Create a custom SAML 2.0 app in your IdP with the ACS URL and Entity ID, and send these attributes:

Attribute Required Also accepted
User.email Yes http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
User.firstName Yes http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
User.lastName No http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname

Attribute names aren't case-sensitive. Then download the IdP metadata XML file.

  1. Create a new app with Platform set to Web and Sign in Method set to SAML 2.0.

    Okta Add Application page with the Create New App button

    Okta Create a New Application Integration dialog with Platform set to Web and SAML 2.0 selected

  2. Set Single Sign On URL to the ACS URL and Audience URI to the Entity ID.

  3. Add attribute statements (name → value): User.emailuser.email, User.firstNameuser.firstName, User.lastNameuser.lastName.

    Okta SAML Settings with Single sign on URL, Audience URI, and User.email, User.firstName, and User.lastName attribute statements

  4. Download the app's Identity Provider Metadata.

    Okta notice with the Identity Provider metadata link

  1. In Enterprise Applications, create a non-gallery application, click Set up single sign on, and select SAML.

    Microsoft Entra ID Select a single sign-on method page with the SAML option

  2. In Basic SAML Configuration, set Identifier (Entity ID) to the Entity ID and Reply URL (Assertion Consumer Service URL) to the ACS URL.

    Basic SAML Configuration card with the Edit button

    Basic SAML Configuration with Identifier (Entity ID) and Reply URL filled in

  3. In User Attributes & Claims, add these claims (claim name → source attribute): User.emailuser.mail, User.firstNameuser.givenname, User.lastNameuser.surname. The screenshot's lowercase names also work.

    User Attributes & Claims card with the Edit button

    User Attributes & Claims page listing the user.email, user.firstname, and user.lastname claims

  4. In SAML Signing Certificate, download Federation Metadata XML.

  5. Optional: in Users and Groups, add the users who can sign in.
  1. In the Admin console, go to Apps > Web and mobile apps > Add app > Add custom SAML app.

    Google Admin custom SAML app details with the app name Jump Desktop

  2. Download the IdP metadata.

  3. Set ACS URL to the ACS URL and Entity ID to the Entity ID.

    Google Admin Service provider details with ACS URL and Entity ID filled in

  4. Add attribute mappings: Primary EmailUser.email, First NameUser.firstName, Last NameUser.lastName.

    Google Admin attribute mappings for Primary email, First name, and Last name

  1. Add the SAML Test Connector (Advanced) app.

    OneLogin app search result for SAML Test Connector (Advanced)

  2. In Configuration, set Audience to the Entity ID, and Recipient, ACS (Consumer) URL Validator, and ACS (Consumer) URL to the ACS URL.

    OneLogin Configuration page with Audience, Recipient, ACS URL Validator, and ACS URL filled in

  3. In Parameters, add User.email (Email), User.firstName (First Name), and User.lastName (Last Name), each with Include in SAML assertion checked.

    OneLogin New Field dialog for User.email with Include in SAML assertion checked

    OneLogin Edit Field dialog with User.email set to Email

    OneLogin Parameters page listing User.email, User.firstName, and User.lastName

  4. Click More Actions > SAML Metadata to download the metadata.

    OneLogin More Actions menu with SAML Metadata

  1. Add a Custom SAML App.

    JumpCloud application search showing Custom SAML App with a configure button

  2. In Single Sign-On Configuration, set IdP Entity ID and SP Entity ID to the Entity ID, and ACS URL to the ACS URL.

    JumpCloud Single Sign-On Configuration with IdP Entity ID, SP Entity ID, and ACS URL filled in

  3. In User Attribute Mapping, add User.email, User.firstName, and User.lastName.

    JumpCloud User Attribute Mapping for User.email, User.firstName, and User.lastName

  4. In User Groups, select who can sign in. Click Activate.

  5. Open the app's Single Sign On Configuration and click Export Metadata.

    JumpCloud applications list showing the new SAML app as active

    JumpCloud app details with the Export Metadata button

  1. In the Teams dashboard, click Manage SAML SSO > Download SP Metadata.
  2. In AD FS Management, add a claims-aware Relying Party Trust and import the SP metadata file.

    AD FS Management with Add Relying Party Trust in the Relying Party Trusts menu

  3. Add a Send LDAP Attributes as Claims rule: E-Mail-Addressesuser.email, Given-Nameuser.firstname, Surnameuser.lastname.

    Edit Claim Issuance Policy dialog with the Add Rule button

    Send LDAP Attributes as Claims rule mapping E-Mail-Addresses, Given-Name, and Surname

  4. Add a Transform an Incoming Claim rule: Windows account nameName ID, format Transient Identifier.

    Transform an Incoming Claim rule from Windows account name to Name ID with Transient Identifier format

  5. In the trust's Properties > Encryption, click Remove to remove the certificate.

    Relying Party Trusts context menu with Properties

    Relying party trust Encryption tab with an encryption certificate and the Remove button

    Encryption tab after the certificate is removed

  6. Download https://<your-adfs-server>/FederationMetadata/2007-06/FederationMetadata.xml.

  1. In Apps & Widgets > Web Apps, add a custom SAML app.

    CyberArk Identity Administration menu with Web Apps under Apps & Widgets

    CyberArk Web Apps page with the Add Web Apps button

    CyberArk Add Web Apps Custom tab with the SAML template

    CyberArk confirmation to add the SAML web app

  2. In Trust, enter the Entity ID and ACS URL, and download the metadata file.

  3. In SAML Response, add attributes User.email, User.firstName, and User.lastName mapped to the user's email, first name, and last name.

    CyberArk SAML Response attributes User.email, User.firstName, and User.lastName

  4. Add users or roles under Permissions, then save.

3. Upload the IdP metadata

  1. On your team's Security page, click Manage SAML SSO.
  2. Click Upload IDP Metadata and choose the file.

Team Single Sign On shows "Single sign on is enabled for your team."

Every existing user links SSO to their account once. Do it yourself first to test the setup.

  1. Sign in to the Teams dashboard with your current account.

    Jump Desktop sign-in page with email and password fields

  2. In the sidebar, click Security (your account's page, not the team's).

    Dashboard sidebar with Security

  3. In Single Sign On, click Sign in with SSO.

    Account Security page with the Sign in with SSO button in the Single Sign On card

  4. Enter your SSO company name, click Continue, and sign in at your IdP.

Your company account appears under Single Sign On. Your IdP email must match your Jump Desktop account email.

5. Require SSO (optional)

Link SSO to your own account first.

  1. In Team Single Sign On, select Require SSO for 'team name' team.
  2. Click Require SSO.

Members who haven't linked SSO are prompted to at their next sign-in.

Rename the SSO company name

  1. In Team Single Sign On, click the pencil icon next to the company name.
  2. Enter the new name (4 to 32 lowercase letters and numbers), click Rename, then Yes, Rename.

The old name stops working, so tell your users the new one. The ACS URL and Entity ID don't change, so your IdP needs no changes.

Limitations

  • Users can't deactivate SSO on their account while they belong to a team that requires SSO.