FAQ for Getting Started with Single Sign-on (SSO)

To find answers to frequently asked questions about getting started with SSO, select a question to jump to its answer. If you don't see your question here, check the FAQs for setting up SSO and troubleshooting.

Does SSO Support Multiple Identity Providers (IdPs) at Once?

No. Organizations can only use one IdP per site ID. Your site ID is the Blackbaud customer identifier that you use for Support and training purposes. You can claim multiple email domains to associate with your IdP. After you enable the SSO connection, you can change the IdP as necessary.

Is SSO the Only Way to Require Multi-factor Authentication (MFA)?

Yes. Organization admins can't enforce or disable MFA for users through Blackbaud ID, which allows individual users to implement MFA themselves. Blackbaud enforces MFA on our solutions, but to require and manage MFA for users, admins must set up user authentication with SSO through an IdP. Then all users can use MFA to sign in through the SSO connection.

Does SSO Manage Access to All My Blackbaud Environments and Solutions?

Yes. SSO configuration is for use with any solution that uses Blackbaud ID. Therefore, users with a single Blackbaud ID can access multiple solutions and multiple databases, and they use the same Blackbaud ID to access all databases that they are invited to.

Does SSO Impact Inactivity Timeouts?

No. Blackbaud's built-in inactivity timeouts remain the same, and users need to sign in again if they are signed out.

How Do Vendors and Blackbaud Consultants Access Our Environment?

If vendors or consultants need access to your solution, invite them so that they can connect using their Blackbaud IDs.

Can We Enforce SSO-only Logins?

Yes. You enforce SSO for all Blackbaud IDs on a claimed domain. When you enable SSO, anyone with a Blackbaud ID on your claimed domains is redirected to your organization's login to sign in through your IdP.

Should We Set Up SSO If Google Is Our IdP?

Yes. While users can select Sign in with Google on the Blackbaud ID sign-in page to use social sign-in even if you don't set up SSO, your organization and its users won't get the benefits and added security of SSO unless you turn on an SSO connection.

If you rely on social sign-in even though Google is your IdP, users can edit their Blackbaud IDs to stop signing in with Google and then sign in through Blackbaud's authentication service using passwords that they manage on their own. If an admin later disables user accounts in the IdP, those users can still sign in to their Blackbaud IDs, so admins need to take additional steps to prevent users from accessing the organization's resources and the solutions associated with their Blackbaud ID accounts.

How Do We Recover If the SSO Configuration Breaks?

Before you enable SSO, we strongly recommend that you create at least one organization admin with a Blackbaud ID email address that is outside of your claimed domains. This admin account acts as your "back door" to manage SSO settings without signing in through SSO. Without it, no one has access to manage your SSO settings if you turn off SSO or errors occur with the domain, and you will have to contact Blackbaud Support to resolve issues, which prolongs downtime for your organization.

Does SSO Automatically Grant Access to Blackbaud Solutions?

No. SSO grants authentication to Blackbaud ID but not authorization to Blackbaud solutions. For users to access the Blackbaud solutions leveraged by your organization, admins need to invite them to those solutions.

How Do I Contact Blackbaud Support?

This help content aims to answer all your questions about Blackbaud ID, but you can also get help from Blackbaud Support.