SAML tab fields
The SAML tab has four sections.Connection
Identity Provider Configuration
Attribute Mapping
Zenskar SAML Configuration Values
Field validation
Checked when Save Configuration is clicked.Zenskar’s SAML values
Copy both from the SAML tab rather than constructing them. The ACS URL uses the production organization’s ID.
Domain verification
Zenskar issues a DNS TXT record to prove control of the email domain.
VERIFY DOMAIN queries DNS for that TXT record and sets the status to Verified when the value is found. Otherwise the status stays Pending.
Sign-in routes to the identity provider only for a Verified domain. An unverified domain falls back to email-and-password sign-in even when the rest of the configuration is filled in and SAML Status is on.
The SAML assertion Zenskar expects
Sign-in behavior
Sign-in is SP-initiated. Users must start at the Zenskar sign-in page. Starting from a tile or deep link inside the identity provider does not complete sign-in.Applying changes
The identity provider connection is created or updated only when the configuration is saved with SAML Status on. Saving with SAML Status off stores the values but does not change the live connection.User provisioning
- Once the domain is Verified and SAML Status is on, users invited to the organization are not sent a password-setup email. Their account is created on first SSO sign-in.
- A user who already has a Zenskar password is asked once, on their first SSO sign-in, to link SSO to their account by confirming that password.