Scope
This article applies to Signals Notebook administrators whose tenant is integrated with SAML-based Single Sign-On (SSO). If your tenant only uses the native Signals Authentication, this article does not apply.
Problem
With a Signals Notebook tenant integrated with Single Sign-On (SSO), even if users have already signed in to the corporate SSO and have an active SSO session, opening Signals Notebook prompts users to re-authenticate.
Solution
This behavior is likely caused by the "Force user authentication" setting being enabled in your tenant configuration. Please verify the following configuration in Signals Configuration in your tenant.
- Navigate to Signals Configuration → System Settings.
- Click "Authentication" in the left navigation panel.
- In the "Domain Name" field, select the URL users access the tenant with via SAML authentication. The page will expand to show SAML settings for the selected URL.
- Scroll down and locate "Force user authentication".
- Uncheck this option to allow users with an active SSO session to bypass re-authentication.
- Click the [Save Settings] button to save the change.
Technical Details about "Force user authentication"
By disabling "Force user authentication", Signals Notebook includes ForceAuthn='false'in the SAML Request sent to the Identity Provider (IdP). The IdP should allow users to reuse the active SSO session without re-authenticating per this SAML Request.
Comments
0 comments
Article is closed for comments.