IcePanel Docs
  • 🧊Welcome
  • 🏁Getting started
  • Core Features
    • Modelling
      • Model objects view
      • Connections list
      • Groups
    • Diagramming
      • Diagrams section
    • Organizations
    • Landscapes
    • Domains
    • Global search
    • Dependencies view
    • Imports
    • Exports
  • COLLABORATION
    • Comments
    • Share links & embeds
  • Ownership teams
  • Roles & permissions
  • Visual Storytelling
    • Flows
      • Flows section
    • Tags
    • Technology choices
  • Future state design
    • Drafts
    • Versioning
  • Reality linking and integrations
    • Linking to reality
    • Code repo linking
      • GitLab
      • GitHub
      • Bitbucket Server
      • Azure DevOps
    • Inaccuracy score
    • REST API
  • 🎓Expert help
    • Training
    • Pilot
  • 🎨Templates
    • IcePanel
    • E-commerce
    • Low-code
    • Marketplace
    • RSS feed
    • Bank
  • ❓Other information
    • Glossary
    • SSO - SAML
    • UI theme
    • Hotkeys
    • Troubleshooting
Powered by GitBook
On this page
  • Getting started
  • SSO share links
  • Identity providers
  • Google Workspace
  • Microsoft Entra ID
  • Okta

Was this helpful?

  1. Other information

SSO - SAML

PreviousGlossaryNextUI theme

Last updated 2 months ago

Was this helpful?

IdP initiated login is not supported yet due to a limitation with our auth provider so you'll need to use the . A workaround could be to add the SAML login page as a web link to your SSO portal.

Track the request to add IdP initiated login on our .

Configuring single sign using SAML integrates IcePanel with your organizations identity provider. This allows users in your organization to securely and easily sign in to IcePanel without the need to manage additional credentials.

Getting started

Instructions can vary based on your SAML identity provider. See examples for below.

Create a new SAML application in your identity provider with the following info.

  • ACS URL / Reply URL - https://app.icepanel.io/__/auth/handler

  • Entity ID / Identifier - icepanel.io

Then fill out our with the requested information from your app. Once that's submitted, it can take up to 1 business day for us to configure it. We'll be in touch shortly to confirm and check everything is working.

Note: IdP initiated login is not supported yet so you'll need to use the .

SSO share links

Once you've configured a SAML app with us you can globally secure access to share links with SSO.

In organization management you can set one or more domains that can access your share links securely. The example below will restrict all share link access to users who authenticate with @icepanel.io email addresses.

Configure SAML SSO

Users will now be redirected to your SAML authentication flow before gaining access to a share link. They will not be required to create an IcePanel account, so these users will not count toward your plan seat count in any way.

Identity providers

We support all identity providers that support SAML 2.0.

Google Workspace

  1. Click Add app / Add custom SAML app.

  2. Set the ACS URL field to https://app.icepanel.io/__/auth/handler.

  3. Set the Entity ID field to icepanel.io.

  4. Set the Name ID format field to EMAIL and the Name ID field to Primary email.

  5. Click the User access section and check the toggle for ON for everyone.

  6. Done, now wait for us to let you know it's all setup on our end.

Microsoft Entra ID

  1. Click Enterprise applications from the left sidebar.

  2. Click New application and pick the Non-gallery application type.

  3. Click Single sign-on in the left sidebar and choose the SAML method.

  4. Click the edit pencil in the Basic SAML configuration.

  5. Set the Identifier (Entity ID) field to icepanel.io.

  6. Set the Reply URL (Assertion Consumer Service URL) field to https://app.icepanel.io/__/auth/handler.

  7. Click Users and groups in the left sidebar and add the users or groups that need access to IcePanel.

  8. Done, now wait for us to let you know it's all setup on our end.

Okta

  1. First navigate to Admin > Applications on the Okta portal.

  2. Click Add New App and select SAML 2.0.

  3. Set the Single sign on URL field to https://app.icepanel.io/__/auth/handler.

  4. Set the Audience URI (SP Entity ID)to icepanel.io.

  5. Set the Name ID format to email address and the Application usernameto email.

  6. Click View setup instructions get the necessary information.

  7. Make sure the required users or groups have permission to access to the Okta app.

  8. Done, now wait for us to let you know it's all setup on our end.

First navigate to Apps / Web and mobile apps on the .

Fill in the app name as IcePanel and upload the .

Copy the values from the SSO URL, Entity ID and Certificate fields into our .

First navigate to Entra ID on the .

Fill in the app name as IcePanel and upload the .

Copy the Certificate (Base64), Login URL and Azure AD Identifier fields into our .

Copy the values from the SSO URL, Identity Provider Issuer (Entity ID) and Certificate fields into our .

Google Admin console
IcePanel logo
SAML registration form
Microsoft Entra ID portal
IcePanel logo
SAML registration form
SAML registration form
❓
SAML login page
feedback board
SAML registration form
SAML login page
identity providers
Page cover image