| Plan | × Professional × Advanced × Scale ✓ Enterprise |
Single sign-on (SSO) lets your team log in to Vista Social through your organization's identity provider (IdP) using SAML 2.0. SSO is available on the Enterprise plan and works on both web and mobile.
What SSO does
- Stronger account security: when someone's role, access, or employment status changes, your admins can remove their access from your identity provider in one step.
- Simpler logins: your team uses one set of company credentials instead of managing a separate Vista Social password.
- Web and mobile support: SSO works in the Vista Social web app and mobile app.
Supported identity providers
Vista Social directly supports:
- OneLogin
- Okta
- Azure AD
If your identity provider isn't listed, it may still work as long as it supports SAML 2.0.
What your IT team needs to know
Your IT or security team will set up Vista Social as a SAML application in your identity provider. Share the details below with them before you start.
Supported protocols and bindings
- SAML 2.0
- IdP-initiated SSO
- SP-initiated SSO
- HTTP Redirect and HTTP POST bindings
SAML requirements
- The SAML response subject's NameID must use
emailAddress. - If an unspecified NameID is used, an
emailAddressattribute must also be provided. - A signing certificate is required.
Information Vista Social provides
We generate a metadata file for your domain (sometimes called the manifest XML). It includes:
- Issuer / entity ID: unique to each email domain
- Assertion consumer service (ACS) URL
How to set up SSO
- Choose your technical contact. Decide who on your IT or security team will handle the SSO setup, then reach out to our support team and share their contact details. We work directly with this person for the rest of the setup.
- Confirm your email domain. Your technical contact confirms the email domain you want to enable SSO for (for example, yourcompany.com).
- Receive your Vista Social metadata file. We generate a metadata file for your domain and send it to your technical contact.
-
Configure your identity provider. Your technical contact uses the metadata file to set up Vista Social as a SAML application, then sends us:
- Your SAML identity provider metadata (file or metadata URL)
- Your signing certificate
- We finish the configuration. Our team completes the setup on our side and confirms once SSO is ready for your domain.
Important notes
- Once SSO is enabled, users on the configured domain must log in with SSO. The email and password login option no longer works for them.
- Users on an SSO domain can't reset their Vista Social password. Passwords are managed in your identity provider.
- Users on an SSO domain can't set up Vista Social two-factor authentication (2FA).
- SSO is set up per email domain. To enable SSO for multiple domains, contact your account manager. The SSO add-on can be customized to fit your organization's needs.
- Our support team can't configure your identity provider for you. The IdP side of the setup is handled by your IT or security team.
Best practices
- Loop in your IT or security team early and share this article with them.
- Make sure everyone who needs access uses an email address on the SSO domain.
- Let your team know ahead of time that their login method is changing, so no one is caught off guard by the email and password login no longer working.
Frequently Asked Questions
Q: Is SSO available on all Vista Social plans?
A: No. SAML 2.0 SSO is available on the Enterprise plan.
Q: What do I need to provide to get started?
A: The contact details of your technical contact (someone on your IT or security team) and the email domain you want to set up SSO for. We'll send your technical contact a metadata file for your domain, and they take it from there.
Q: Does Vista Social support my identity provider?
A: Vista Social directly supports OneLogin, Google, Okta, and Azure AD. Other identity providers may also work if they support SAML 2.0 and meet the SAML requirements above.
Q: Do I need an IT administrator to configure SSO?
A: Yes. SSO requires configuration in your identity provider, so we recommend working with your organization's IT or security team.
Q: Can Vista Social support configure my identity provider for me?
A: No. Our support and engineering teams can't provide one-on-one help configuring your identity provider. Your IT or security team, or your identity provider, should handle that part of the setup.
Q: I set up SSO. Can I still use my Vista Social password?
A: No. Once SSO is configured for your domain, email and password login no longer works, and you won't be able to reset your Vista Social password.
Q: Can I use SSO for multiple domains?
A: Yes. Contact your account manager, and we'll customize the SSO add-on to fit your organization's needs.
Need help?
Reach out to our support team, and we are happy to help.
Related Reading:
Ways to log in to Vista Social
My Vista Social account is locked out
Sign up now and try Vista Social for 14 days, free!