Configure SAML Single Sign-On for an Organization
Let your team sign in to a Mondoo organization through your identity provider over SAML 2.0.
With SAML single sign-on (SSO), people sign in to a Mondoo organization through your identity provider (IdP) instead of a Mondoo password or a Google, GitHub, or Microsoft account. Mondoo supports any IdP that speaks SAML 2.0, such as Okta, Microsoft Entra ID, Google Workspace, and OneLogin. You configure SSO for each organization on the organization's Authentication settings page.
SAML SSO depends on your Mondoo plan. If your plan doesn't include it, the Authentication page shows Single sign-on isn't on your plan and a CONTACT SALES button instead of the SSO settings.
SAML SSO only handles sign-in. It doesn't create users or grant them access. Add people and assign their roles as described in Manage team members, or assign access through OIDC group claims and teams.
Prerequisites
- A Mondoo plan that includes single sign-on
- The Admin role or the IAM Manager permission in the organization
- Administrator access to your IdP, so you can create a SAML application for Mondoo
Step 1: Create a SAML application in your IdP
In your IdP, create a SAML 2.0 application for Mondoo. The exact steps depend on your IdP. Collect these values from it, because you enter them in Mondoo in the next step:
| Value in your IdP | Where it goes in Mondoo |
|---|---|
| Single sign-on URL (SSO URL) | Single Sign-On URL |
| IdP entity ID (issuer) | Identity Provider Entity ID |
| Signing certificate (X.509, PEM) | X.509 Certificates |
| Audience / service provider entity ID | Service Provider Entity ID |
The service provider entity ID is a name you choose to identify Mondoo in your IdP (the audience of the SAML assertion). Use the same value in your IdP and in Mondoo.
For the application's assertion consumer service (ACS) URL, also called the reply URL, use https://auth.mondoo.com/__/auth/handler.
Step 2: Configure the identity provider in Mondoo
-
Navigate to the organization.
-
In the side navigation bar, select Settings, then Authentication.
-
Next to SAML 2.0 Connection, select Configure.
-
Fill in the SSO > Identity Provider form:
-
Single Sign-On URL: your IdP's SSO URL.
-
Identity Provider Entity ID: your IdP's entity ID.
-
Service Provider Entity ID: the entity ID you gave the Mondoo application in your IdP.
-
X.509 Certificates: select Add Certificate and paste your IdP's public signing certificate. The value must start with
-----BEGIN CERTIFICATE-----and end with-----END CERTIFICATE-----.
-
-
Select Save.
Step 3: Turn on SSO
After you save a configuration, the SAML 2.0 Connection switch becomes available. Turn it on to let people sign in through your IdP. Turn it off to disable SSO sign-in for the organization without deleting the configuration.
Sign in with SSO
The Authentication page shows the organization ID under Name. People sign in with that ID:
-
On the Mondoo sign-in page, select SSO.
-
In the Organization ID box, enter your organization ID.
-
Select Continue with SSO and complete the sign-in at your IdP.
Rotate the signing certificate
You can keep more than one certificate on the configuration, so you can rotate your IdP's signing certificate without interrupting sign-in:
-
On the organization's Authentication page, select Configure.
-
Select Add Certificate, paste the new certificate, and select Save. Mondoo lists saved certificates by their fingerprint (Certificate #1, Certificate #2, and so on).
-
Switch your IdP to sign with the new certificate.
-
Return to the Authentication page, select Configure, remove the old certificate, and select Save.
Related
- To provision users and groups from Microsoft Entra ID or Okta on a privately hosted Mondoo instance, read Manage access with Entra (SCIM) or Manage access with Okta (SCIM).
- To assign Mondoo teams from your IdP's groups, read Manage access with OIDC group claims and teams.
Manage Team Members
Invite team members and assign roles to control access to Mondoo organizations and spaces.
Manage Access with OIDC Groups
Automatically assign users to Mondoo teams based on identity provider group membership using OIDC group claims. An alternative to SCIM that requires no provisioning infrastructure.