Gather SAML Metadata
To setup a SAML Identity Provider for use as EchoMark SSO, you will need to get the Federated Metadata XML document. Most SAML providers will have an easy way to download this XML file.
Your SAML provider may also require an Identifier (Entity ID) and/or a Reply URL (Assertion Consumer Service URL). If so, you can use the following values:
Identifier: https://app.echomark.com
Reply URL: https://app.echomark.com/api/oauth/saml
Note: For single-tenant customers, replace “app.echomark.com” with your custom domain
Setup SSO Provider in EchoMark
There are two ways you can use to setup and SSO Provider within EchoMark.
- Use the “Set up Single Sign-On on EchoMark” email sent to you to configure SSO.
- Click on the Start SSO Configuration button in the email. Then, continue with Step 3 below.
- If you already have an account setup, and are an Admin user in EchoMark, you can set up a new SSO provider through the EchoMark application.
- Log into the EchoMark application
- Go to the Settings page
- Click on the Authentication link in the left Settings menu
- There are two ways to setup the SSO provider from here. You can either invite an IT or SSO administrator to setup the SSO provider via an invite email or you can setup the SSO provider yourself.
- To invite an IT or SSO administrator to setup the SSO provider, click on the Invite IT admin to set up SSO provider button.
- To invite an IT or SSO administrator to setup the SSO provider, click on the Invite IT admin to set up SSO provider button.
Fill in the IT/SSO administrator’s email address, and if desired modify or delete the additional personal message. Then click on the Send invitation button to send the email invitation.
- To setup the SSO provider yourself, click on the Add SSO provider button.
- In the following dialog, fill in the fields:
- Friendly name – Any friendly name you’d like displayed to differentiate this SSO provider from any others you may create.
- Provider Type – Select SAML
- Metadata – Either copy and paste the XML data for your SAML provider, or click on the in the box to upload a Federated Metadata XML file that you received from your SSO provider.
- Email domains - Add in at least one email domain that should be associated with this SSO provider. Email domains will differentiate which SSO provider should be used to log into your EchoMark account. To add an email domain, enter the domain (such as “example.com”) in the box, and click on the Add button when it turns blue to indicate it is enabled. Note domains must be unique across the environment, and must be associated with your company.
- Then, click on the Continue button to save your configuration.
- On the next screen, review the provider type and email domain(s) associated with the SSO provider. If you need to still setup your SAML provider with an identifier or a Reply URL, you can copy those values from this screen as well. Then click on the Enable SSO and test button to enable the SSO provider. Note: Once you click on this button, this provider will be enabled immediately for testing purposes. You can disable it if needed after testing.
- Verify that the login works. If this is the only SSO provider for your organization, or you are logged into the EchoMark application with a user of the same SSO provider, it is recommended that you just try to log in from an incognito or private browser window to avoid being locked out. Otherwise, you can click on the Open test sign-in button to open a new tab on the login page. This will log you out of your current session. In either case, once you verify that the login is working, click on the It worked button to complete the configuration. If login did not work with the new SSO provider, you can click on the It didn’t work – disable SSO button to disable the new provider.
- If the test was successful, you will see a confirmation dialog box. Click on the Done button to close it. Users can now login using the newly configured SSO provider.
- If the test is not successful, then clicking the It didn’t work – disable SSO button will immediately disable the new provider and bring up a confirmation box. You can click on the Done button to close it, or the Edit my configuration to return to the SSO provider configuration page to make changes and try again.