SSO / SAML Setup
Configure SAML single sign-on for your organization
WAF360 supports SAML 2.0 single sign-on (SSO), allowing your team to authenticate through your organization's identity provider (IdP) such as Okta, Azure AD, or Google Workspace.
- A WAF360 organization with Master access
- A SAML 2.0 compatible identity provider
- IdP metadata (Entity ID, SSO URL, Logout URL, X509 Certificate)
- Navigate to your organization in the sidebar
- Click SSO in the navigation
- Click on SAML to open the configuration page
The connection status shows Active (green) if SAML is configured, or Inactive (gray) if not.
Toggle to activate or deactivate SAML authentication for your organization.
When enabled, users in your organization can only log in through SAML SSO. Standard email/password login is disabled.
Use caution when enabling this option. Ensure your SAML configuration is working correctly before disabling password login.
Enter your organization's email domain (e.g., example.com). This is used to route users to the correct SSO login.
| Field | Description |
|---|
| Entity ID of IDP | The unique identifier for your identity provider |
| Login URL of IDP | The SSO login endpoint URL |
| Logout URL of IDP | The SSO logout endpoint URL |
| X509 Certificate of IDP | The public certificate from your IdP for signature verification |
Optionally restrict which users can access WAF360 through SAML:
- Leave empty to allow all users from your IdP
- Add email addresses to restrict access to specific users only
Use the add/remove buttons to manage the allowed user list.
- Configure your IdP — In your identity provider (Okta, Azure AD, etc.), create a new SAML application for WAF360
- Collect IdP metadata — Note your Entity ID, Login URL, Logout URL, and download the X509 certificate
- Enter configuration — Fill in all required fields in the WAF360 SAML settings
- Set your domain — Enter the email domain used by your organization
- Enable SAML — Toggle the enable switch
- Test login — Open a new browser window and test SSO login before disabling password login
- (Optional) Disable password login — Once confirmed working, optionally disable password-based login
Once SAML is configured, users can log in via SSO:
- On the WAF360 login page, click the SSO login option
- Enter the organization's domain
- The user is redirected to the IdP for authentication
- After successful authentication, the user is redirected back to WAF360
- Cannot log in via SSO — Verify the IdP Login URL and Entity ID are correct
- Certificate errors — Ensure the X509 certificate is complete and properly formatted
- Locked out after disabling password login — Contact [email protected] for assistance