Skip to main content

Configure SAML single sign-on (SSO)

Settings guide

Set up SAML single sign-on (SSO) so users authenticate to NIM through your existing identity provider instead of managing a separate NIM password.

SAML single sign-on (SSO) in NIMDirect link to SAML single sign-on (SSO) in NIM

SAML is the protocol NIM uses for single sign-on (SSO). With SAML SSO, users sign in to NIM through an identity provider (IdP) such as Microsoft Entra ID, Google Workspace, or Okta. This centralizes authentication and can apply the same sign-in policies, including multifactor authentication, that your organization already uses.

In the SAML exchange, NIM is the service provider (SP) and your sign-in platform is the IdP. The IdP issues an assertion that NIM uses to identify the user; metadata supplies the endpoints and certificates that let the two sides communicate. The OASIS SAML 2.0 Technical Overview explains these roles and the browser SSO flow. When troubleshooting, check the IdP metadata, assertion signing certificate, and user identifier against the values configured on both sides.

Before you beginDirect link to Before you begin

SAML can authenticate users through providers such as Microsoft Entra ID, Google Workspace, or Okta. Each user must exist in NIM’s Internal users table with a matching email address or username. To restrict a user to a specific SAML configuration, set AuthMethod to saml<configuration name>, such as samlEntra for a configuration named Entra. If AuthMethod is undefined, the user can use any authentication method configured in NIM. See Internal user AuthMethod rules.

Configure SAML SSODirect link to Configure SAML SSO

Create matching Internal usersDirect link to Create matching Internal users

Provision the intended users to the Internal system. To require SAML-only sign-in, set AuthMethod to saml followed by the name of the SAML configuration you will create.

Step 1 of 3
tip

Keep a local administrator recovery path until SAML authentication has been tested successfully.

Renew identity-provider metadata after certificate expirationDirect link to Renew identity-provider metadata after certificate expiration

When the certificate in your identity provider’s SAML metadata expires or is renewed, obtain a current metadata file from the identity provider and upload it to the existing NIM SAML configuration. This refreshes the identity-provider metadata used by NIM; you do not need to create a new SAML configuration for the same identity provider.

  1. Get the current metadata file from your identity provider.
  2. In NIM, go to Configuration > Settings.
  3. Select the SAML tab.
  4. Edit the existing SAML configuration.
  5. Select the IdP tab.
  6. Upload the current file in IdP Metadata.
  7. Select Update to save the configuration.

After saving, test sign-in with a controlled non-administrator user before relying on the renewed configuration for broader access. Keep the prior metadata file until the test succeeds, according to your organization’s change and retention process.

Configure Microsoft Entra ID SAMLDirect link to Configure Microsoft Entra ID SAML

Enable SAML in Entra IDDirect link to Enable SAML in Entra ID

In Microsoft Entra ID, create your own enterprise application and enable Single sign-on > SAML. In the SAML settings, set Verification Certificates – Required to No and clear Signed authn requests on the SP settings.

Step 1 of 4

Configure Google Workspace SAMLDirect link to Configure Google Workspace SAML

Start a custom SAML appDirect link to Start a custom SAML app

In Google Workspace, create a custom SAML application and download its IdP metadata.

Step 1 of 3