Configure SAML single sign-on (SSO)
Settings guide
Set up SAML single sign-on (SSO) so users authenticate to NIM through your existing identity provider instead of managing a separate NIM password.
SAML single sign-on (SSO) in NIMDirect link to SAML single sign-on (SSO) in NIM
SAML is the protocol NIM uses for single sign-on (SSO). With SAML SSO, users sign in to NIM through an identity provider (IdP) such as Microsoft Entra ID, Google Workspace, or Okta. This centralizes authentication and can apply the same sign-in policies, including multifactor authentication, that your organization already uses.
In the SAML exchange, NIM is the service provider (SP) and your sign-in platform is the IdP. The IdP issues an assertion that NIM uses to identify the user; metadata supplies the endpoints and certificates that let the two sides communicate. The OASIS SAML 2.0 Technical Overview explains these roles and the browser SSO flow. When troubleshooting, check the IdP metadata, assertion signing certificate, and user identifier against the values configured on both sides.
Before you beginDirect link to Before you begin
SAML can authenticate users through providers such as Microsoft Entra ID, Google Workspace, or Okta. Each user must exist in NIM’s Internal users table with a matching email address or username. To restrict a user to a specific SAML configuration, set AuthMethod to saml<configuration name>, such as samlEntra for a configuration named Entra. If AuthMethod is undefined, the user can use any authentication method configured in NIM. See Internal user AuthMethod rules.
Configure SAML SSODirect link to Configure SAML SSO
Create matching Internal usersDirect link to Create matching Internal users
Provision the intended users to the Internal system. To require SAML-only sign-in, set AuthMethod to saml followed by the name of the SAML configuration you will create.
Enter identity-provider detailsDirect link to Enter identity-provider details
Go to Configuration > Settings > SAML, select Add, name the configuration, and provide the metadata or issuer, sign-in URL, certificate, and identifier values supplied by the identity provider.
Validate with a controlled userDirect link to Validate with a controlled user
Save and test sign-in with a non-administrator account first. Confirm the provider assertion matches the NIM user identifier before enabling the configuration for broader use.
Keep a local administrator recovery path until SAML authentication has been tested successfully.
Renew identity-provider metadata after certificate expirationDirect link to Renew identity-provider metadata after certificate expiration
When the certificate in your identity provider’s SAML metadata expires or is renewed, obtain a current metadata file from the identity provider and upload it to the existing NIM SAML configuration. This refreshes the identity-provider metadata used by NIM; you do not need to create a new SAML configuration for the same identity provider.
- Get the current metadata file from your identity provider.
- In NIM, go to Configuration > Settings.
- Select the SAML tab.
- Edit the existing SAML configuration.
- Select the IdP tab.
- Upload the current file in IdP Metadata.
- Select Update to save the configuration.
After saving, test sign-in with a controlled non-administrator user before relying on the renewed configuration for broader access. Keep the prior metadata file until the test succeeds, according to your organization’s change and retention process.
Configure Microsoft Entra ID SAMLDirect link to Configure Microsoft Entra ID SAML
Enable SAML in Entra IDDirect link to Enable SAML in Entra ID
In Microsoft Entra ID, create your own enterprise application and enable Single sign-on > SAML. In the SAML settings, set Verification Certificates – Required to No and clear Signed authn requests on the SP settings.
Use the assigned application certificateDirect link to Use the assigned application certificate
Under SAML Certificates, download the Federation Metadata XML file.
Do not copy the App Federation Metadata URL. Its certificate can differ from the certificate assigned to the application. Download and upload the Federation Metadata XML file instead.
Upload the identity-provider metadataDirect link to Upload the identity-provider metadata
In NIM, go to Configuration > Settings > SAML, select Add, name the configuration (for example, Azure), upload the Entra metadata file in IdP Metadata, and select Create.
Upload NIM metadata and assign accessDirect link to Upload NIM metadata and assign access
Select the new NIM configuration and download its metadata file. Upload it to the Entra enterprise application to populate the required application values. In Users and groups, assign the users and groups that may sign in to NIM. Confirm affected Internal users use samlAzure as their authentication method when the NIM configuration is named Azure.
Configure Google Workspace SAMLDirect link to Configure Google Workspace SAML
Start a custom SAML appDirect link to Start a custom SAML app
In Google Workspace, create a custom SAML application and download its IdP metadata.
Upload Google metadata to NIMDirect link to Upload Google metadata to NIM
In NIM, go to Configuration > Settings > SAML, select Add, name the configuration (for example, Google), upload the Google IdP metadata file, and select Create. Select the new configuration to obtain the NIM ACS callback URL and metadata URL.
Map the NIM endpoints and user identityDirect link to Map the NIM endpoints and user identity
Return to the Google application and configure:
| Google setting | Value from NIM or Google |
|---|---|
| ACS URL | NIM ACS Callback URL |
| Entity ID | NIM Metadata URL |
| Signed response | Enabled |
| Name ID format | EMAIL |
| Name ID | Basic Information > Primary Email |
Save, assign users, and test with a controlled Internal user whose authentication method is samlGoogle.