Table of Contents

SAML 2

Configuration

Enabling/Disabling SAML authentication requires restarting the application

Example with Microsoft Azure

IDP Metadata example :

Additional Information

First connexion

When a user logs in for the first time using SAML, their account will be created with no authorizations.
It is possible to define default permissions for the first login of a user via the User menu.

Resources available

The Cockpit application can have multiple SAML configurations (one per tenant) based on the registration ID.
Below is a list of available URLs with SAML 2:

Multiple SAML configuration

It is possible to configure a SAML setup for each tenant.
If multiple SAML configurations have been set up, during login, the tenant's domain will be requested from the user to identify which tenant they wish to connect to via SAML.
The domain of a tenant is defined when it is created.

Tenant modal :

Login screen once SAML is configured :

SAML login screen with multiple SAML :