Skip to main content

Administrator Authentication via SAML (SSO)

Administrator authentication via SAML (Security Assertion Markup Language) through Single Sign-On (SSO) is a federated authentication method that allows administrators to access multiple systems and applications with a single login credential. This method improves security and efficiency by eliminating the need to manage multiple passwords and reducing the risks of attacks.

To use this feature, an account with administrator permissions to the Pulsus portal (https://app.pulsus.mobi) is required.

In addition to accessing the Pulsus product, you must also have the information listed below from your SAML provider on hand, or have access to obtain it.

  • Entity

  • SSO URL

  • Certificate (fingerprint)

Data for creating the Pulsus configuration in your authentication provider:

Note: When creating the certificate in your provider, make sure to create it based on the SHA1 or SHA256 algorithm.

With this information at hand, the first step is to access the Pulsus platform and authenticate with your administrator user.

After logging in, access the administrator menu in the top right corner of the screen by clicking on the three dots, and select SAML Access (SSO).

On the next screen, fill in your provider's data.

After entering the information obtained from your SAML provider, click Update.

You're all set! You can now start creating administrators who will authenticate using your SSO provider.

Creating SAML-based administrators (SSO)

To create administrators, simply access the Administrators menu.

On the administrators screen, enter the option to add administrators, represented by the (+) button.

On the screen above, fill in the new administrator's data by entering the active user's e-mail from the SAML provider, and under Login Provider, select your provider registered in the previous step.

From now on, administrators registered with the SAML authentication type simply need to access the Login with SSO option on the login screen to be redirected to your SSO authentication service.

Did this answer your question?