SSO Setup FAQs
NOTE: For details on setting up SSO in Workzone, check out Single Sign-On (SSO)
Sending Proper Attribute Names
Workzone's SSO requires the sending of proper assertion names. Your assertion must include an attribute with a name matching one of the four listed below, and the attribute value must be an email address that matches an established Workzone user account:
- "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"
- "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"
- "urn:oid:1.3.6.1.4.1.5923.1.1.1.6"
- "urn:oid:0.9.2342.19200300.100.1.3"
Without one of those four attributes — containing attribute values with an email address — in place, Workzone will display a 403 error reading "Unable to authenticate via SSO" when attempting to authenticate.
Updating your SSO Certificate
Upload your updated Identity Provider Metadata XML file to complete the updating for Workzone. Please note that every time you upload a new file, it will overwrite all previous configurations.
For any additional assistance with this, please email us at help@workzone.com or call 610-275-9861.