Single Sign-on (SSO)
SSO improves the overall Blackbaud ID user experience by enabling users to move securely between Blackbaud solutions and other cloud services without providing credentials each time. Organizations can enable SSO to manage user access to their Blackbaud solutions and also to enforce secure passwords and other authentication policies. Users sign in through their organization's identity provider (IdP), and the organization manages the users in their claimed domains.
To enable SSO from the Authentication settings page, organization admins select Manage SSO settings under Single sign-on and then select the connection method. After they turn on SSO, organization admins can select Manage SSO settings to access the Single sign-on page to manage the SSO connection. If they don't set up SSO, users must sign in through Blackbaud's secure authentication service or through social sign-in.
This topic covers the following:
Single Sign-on Connection
On the Single sign-on page, you can view SSO connection details, such as the connection name and the application ID, and you can manage SSO details, such as the organization name to display when users sign in.
Claimed Email Domains
To determine which users to redirect to your IdP when they sign in with their Blackbaud IDs, you claim the email domains, such as @yourdomain.org or @yourdomain.edu, that your organization uses. Under Claimed email domains, you can manage the domains that your SSO connection recognizes.
Redirect Settings
To ease authentication after you enable SSO, you can provide users at your organization with a redirect URL to bypass the Blackbaud ID sign-in page and sign in directly through your IdP. You can also create additional redirect URLs to ease access to Blackbaud ID-supported solutions. For more information, see Redirect Settings.