logo
Help Center/Organization/Guide to SAML SSO

Guide to SAML SSO

Motiff supports Single Sign-On (SSO) function. You can use the information from an Identity Provider (IdP) to log in to multiple applications or websites. Motiff uses Security Assertion Markup Language (SAML) as the security standard for managing identity authentication.

SAML SSO is only available for users with the Motiff Organization plan. If your organization has stricter security requirements, you can configure SAML SSO to enhance data security.

When using SAML SSO, organization members can log into their Motiff account through the IdP.

How SAML SSO works

  1. 1.Organization members can log into their Motiff account using SAML SSO.
  2. 2.Motiff sends a SAML request to the IdP.
  3. 3.The IdP checks the member's authentication information.
  4. 4.The IdP sends a response to Motiff, confirming the member's organization identity.
  5. 5.Motiff accepts the response and allows the member to log into their Motiff account.

Note: Motiff uses the SAML 2.0 standard in all SAML SSO configurations.

Configure SAML SSO

Motiff only supports organization admins in configuring SAML SSO. If you are an admin of the design team, it is recommended to collaborate with the IT team to complete the configuration.

Confirm the domain

Motiff distinguishes organization members and guests through domain names.

For example, since a Motiff team registers the domain motiff.com within its organization, users logging in with a motiff.com email are members of the organization and can log in via SAML SSO.

Users whose email accounts do not match the domain are guests and cannot log in via SAML SSO, such as name@gmail.com or name@outlook.com .

Note: If you plan to use SAML SSO, you need to register all domains used in Motiff with the IdP.

Configure SAML SSO in Motiff

Motiff supports custom SAML SSO configurations. You can configure SAML SSO in Motiff by following these steps:

  1. 1.Open the organization in Motiff.
  2. 2.Click Admin in the sidebar and change to Settings.
  3. 3.In the Authentication section, click SAML SSO.
  4. 4.Provide the generated SP Entity ID and SP ACS URL on the page to your IdP, and ensure that the NameId is configured in the following format: urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
  5. 5.Enter the following information provided by the IdP into Motiff:
    • IdP Issuer
    • IdP SSO URL
  6. 6.Obtain the IdP Public Certificate from the IdP and upload it to Motiff. 'SAML SSO.png'
  7. 7.Click Enable SSO.

Tip: The configuration method may vary with different IdPs. You can contact the Motiff support team for further assistance.