| Plan | × Professional × Advanced × Scale ✓ Enterprise |
Vista Social supports SAML 2.0 Single Sign-on (SSO) for Enterprise customers, allowing users to access Vista Social through their organization's Identity Provider (IdP).
This article explains the SSO requirements, supported Identity Providers, and the information your IT or Security team needs to configure SSO for your organization.
|
Note ⚠️ You must set up a passkey on your Vista Social account before you can use Login with passkey. |
Who can use SSO?
SAML 2.0 SSO is available for Enterprise customers.
SSO can be used on both web and mobile platforms.
Benefits of SSO
The primary advantage of implementing SSO is enhanced account security. When an employee's permissions, access privileges, or employment status changes, network administrators can efficiently disable all associated accounts with minimal effort. Furthermore, SSO delivers a smoother login experience by eliminating the need for employees to remember or manage multiple passwords.
Supported Identity Providers
Vista Social directly supports the following Identity Providers (IdPs):
- OneLogin
- Okta
- Azure AD
Vista Social uses SAML 2.0 for SSO. If your Identity Provider is not listed above, it may still be compatible as long as it supports SAML 2.0.
What your IT team needs to know
Your IT or Security team will need to configure Vista Social as an application in your Identity Provider.
Vista Social supports:
- SAML 2.0
- IdP-initiated SSO
- SP-initiated SSO
- HTTP Redirect and HTTP POST bindings
SAML requirements
Vista Social requires the following:
- The SAML Response Subject's NameID must use
emailAddress. - If an unspecified NameID is used, an
emailAddressattribute must also be provided. - A signing certificate is required.
Vista Social configuration information
Vista Social will provide the information required to configure the SAML application, including:
- Issuer / Entity ID — unique to each email domain.
- Assertion Consumer Service (ACS) URL — provided in the manifest XML.
Your IT team can use this information when configuring Vista Social in your Identity Provider.
How to set up SSO
1. Request the Vista Social SSO manifest
Contact Vista Social Support to request the manifest XML required for your SSO configuration.
The manifest contains the Vista Social information your IT team needs to configure the SAML application.
2. Configure Vista Social in your Identity Provider
Provide the manifest to your organization's IT or Security team.
They should use the information in the manifest to configure Vista Social as a SAML application in your Identity Provider.
3. Export your Identity Provider metadata
After configuring the SAML application, your IT team should provide:
- The SAML Identity Provider Metadata file
- The required signing certificate
4. Send the configuration information to Vista Social
Send the Identity Provider Metadata file and signing certificate to Vista Social Support.
Our team will use this information to configure SSO for your domain.
Important things to know before enabling SSO
Once SSO is configured for a domain, users associated with that domain will have some changes to their login options.
Users must log in through SSO
Once SSO is enabled, users will need to use SSO to access Vista Social.
The regular email/password login option will no longer work for users on the configured domain.
Password reset is not available
Users on a domain configured for SSO will not be able to reset their Vista Social password.
Password management should be handled through your organization's Identity Provider.
Vista Social 2FA cannot be configured
Users on a domain configured for SSO will not be able to configure two-factor authentication (2FA) in their Vista Social accounts.
Multiple domains
If you need to enable SSO for multiple email domains, contact your account manager. The SSO add-on can be customized to support your organization's requirements.
Frequently Asked Questions
Q: Is SSO available on all Vista Social plans?
A: No. SAML 2.0 SSO is available for Enterprise customers.
Q: Does Vista Social support my Identity Provider?
A: Vista Social directly supports OneLogin, Google, Okta, and Azure AD. Other Identity Providers may also work if they support SAML 2.0 and meet Vista Social's SAML requirements.
Q: Do I need an IT administrator to configure SSO?
A: Yes. SSO requires configuration in your Identity Provider, so we recommend working with your organization's IT or Security team.
Q: Can Vista Social Support configure my Identity Provider for me?
A: No. Vista Social Support and Engineering teams cannot provide personalized SSO configuration or one-on-one assistance with configuring your Identity Provider. Your organization's IT/Security team or Identity Provider should handle the configuration.
Q: I set up SSO. Can I still use my Vista Social password?
A: No. Once SSO is configured for your domain, the email and password login option no longer works, and you won't be able to reset your Vista Social password.
Q: Can I use SSO for multiple domains?
A: Yes. If you need to enable SSO for multiple domains, contact your account manager. The SSO add-on can be customized to fit your organization's needs.
Need further help?
If you have any questions or need additional help, feel free to contact our awesome support team. We are here to assist you! 💙
Related Reading:
I'm having issues using Google Sign-in in Vista Social
My Vista Social account is locked out
Sign up now and try Vista Social for 14 days, free!