SAML 2.0 Setup

Security Assertion Markup Language (SAML) 2.0 is a standard protocol to exchange authentication data between security domains. To enable your organization's Blackbaud IDs to sign in to Blackbaud solutions through a SAML 2.0 identity provider (IdP), such as Google Workspace, OneLogin, Shibboleth or Central Authentication Service (CAS), create a SAML 2.0 connection and configure its settings in Authentication:

  • Your organization's display name for when users sign in

  • The web address for your SAML 2.0 connection's login

  • The certificate for your SAML 2.0 connection

  • The field names or unique identifiers that your IdP uses to identify users

For details about how to set up a connection for Google Workspace, JumpCloud, or OneLogin, see SAML 2.0 Setup for Google Workspace, SAML 2.0 Setup for JumpCloud, or SAML 2.0 Setup for OneLogin.

To prevent inadvertent lockouts:

  • Complete configuration during a maintenance window for your organization's network.

  • Ensure that you have a Blackbaud ID outside of your claimed domains with access to Authentication.

To clear your setup and start over, select Erase all single sign-on settings. For more information, see Single Sign-on Setup.

If you have issues with your SAML 2.0 connection, see SSO Connection Troubleshooting.