FAQ for Single Sign-on (SSO) Questionnaires
For organizations where IT departments or other stakeholders require you to complete questionnaires before enabling SSO, this FAQ provides answers to common questions. Select a question to jump to its answer. Or for general questions about setting up SSO, see the SSO setup FAQ.
General
-
Does Blackbaud Support Service Provider-initiated or IdP-initiated User Authentication?
-
What Are the URLs for Production, Test, and Just-in-time Provisioning?
-
What Active Directory Values Need to Be Returned As the Default NameID?
-
Do We Need to Apply Specific Custom Attributes of Our Users?
-
Do Custom Attributes Require Case Sensitivity or Additional Formatting?
Connection-specific
Resources
General
What Identity Providers (IdPs) Does Blackbaud Support?
Blackbaud ID supports the following SSO options. Follow the links for detailed instructions.
Can We Use a Test Environment to Test SSO?
No, but Blackbaud provides a test mode so that you can test your SSO connection before you go live. Users can access a test sign-in that sends Blackbaud IDs with your claimed email domains to your IdP, and testing does not impact other users.
Does Blackbaud Support Service Provider-initiated or IdP-initiated User Authentication?
Blackbaud only supports service provider-initiated user authentication. We do not support IdP-initiated user authentication.
What Is the Application Login URL?
The application login URL varies depending on the Blackbaud solution where users are signing in. Our standard sign-in page for all Blackbaud ID users is app.blackbaud.com. This URL redirects users to the Blackbaud ID Welcome page.
What Are the URLs for Production, Test, and Just-in-time Provisioning?
-
Production: app.blackbaud.com/ — plus the solution-specific extension to the URL
-
QA or Test: https://app.blackbaud.com/signin/?ssoTest=true
-
Just-in-time (JIT): app.blackbaud.com — users can be provisioned but are not assigned permissions or access to solutions
What Active Directory Values Need to Be Returned As the Default NameID?
Blackbaud requires a NameID, and we expect the IdP's unique user ID value within the NameID. We recommend against including a user's email. The format is determined based on the NameID SAML assertion on the SSO configuration screen.
Do We Need to Apply Specific Custom Attributes of Our Users?
No. We only require standard fields. You specify these required field mappings on the SSO configuration screen.
Do Custom Attributes Require Case Sensitivity or Additional Formatting?
No. The only formatting requirement is to adhere to SAML assertions.
What Attributes Are Required to Provision an Account?
The following attributes are required for account provisioning:
-
Unique ID
-
First name
-
Last name
-
Email address
Who Do I Contact If My Question Is Not on This Page?
For questions that are unique to your organization, contact Blackbaud Support at support.blackbaud.com or use another method to contact Blackbaud Support.
Connection-specific
Does Blackbaud Provide a Service-provider Metadata File for SAML Configurations?
Yes. We provide the metadata file, and we recommend that you reference the metadata URL with your IdP to make sure that updates to the configuration are automatically understood by both Blackbaud and the IdP.
Are Blackbaud SAML Assertions Signed?
Yes. SAML assertions are signed.
Can Blackbaud SAML Assertions Be Encrypted?
Yes. You can select an option on the SAML configuration screen to encrypt your SAML assertions.
For Shibboleth, Is Blackbaud a Member of InCommon?
No. Blackbaud is not a member of InCommon.
Resources
Who Do We List As the Vendor Contact?
Use "Blackbaud Inc." as the contact name, and send inquiries through Blackbaud Support as necessary at support.blackbaud.com.
What SSO Documentation Does Blackbaud Provide?
The Authentication section of this help file provides detailed information about Blackbaud's SSO options and configuration steps.