FAQ for Setting Up Single Sign-on (SSO)

To find answers to frequently asked questions about setting up SSO, select a question to jump to its answer. If you don't see your question here, check the FAQs for getting started and troubleshooting. If your IT department or other stakeholders require you to complete a questionnaire before enabling SSO, see the FAQ for questionnaires to find answers to common questions.

Can I Replace Blackbaud Branding on the Sign-in Page and User Profile?

Yes. You can edit the display name to update the label for the blue button on the Blackbaud ID sign-in page and the "Authenticated with" label at the top of user profiles.

Does SSO Require Special Precautions?

Yes. Before you enable SSO, we strongly recommend that you create at least one organization admin with a Blackbaud ID email address that is outside of your claimed domains. This admin account acts as your "back door" to manage SSO settings without signing in through SSO. Without it, no one has access to manage your SSO settings if you turn off SSO or errors occur with the domain, and you will have to contact Blackbaud Support to resolve issues, which prolongs downtime for your organization.

If you disable SSO or errors occur after you enable it, you can use this admin account to log in and access your SSO configuration settings. You can also use this admin account if issues with your identity provider or with SSO prevent you from logging in with your organization domain email address.

To create this admin account, add an admin account with an email address that doesn't use your organization's claimed domains. Then log in with it and make sure you can access your SSO settings on the Authentication settings page.

How Is the Change to the Login Experience Communicated to Users?

All users who sign in with Blackbaud IDs for your verified domains receive an email to inform them of the change to their log in experience. The email explains that when they sign in to their Blackbaud solutions, they now need to use the same credentials that they use for other applications that your organization authorizes. The email can't currently be customized.

What Happens When Organizations Use the Same Email Domain?

When you enable SSO, it affects the entire email domain. If multiple organizations with different site IDs share an email domain, configuring SSO for one of them also configures it for the others. It is important to ensure that related organizations on the same email domain coordinate to prepare all users when SSO is enabled. The organization admins of the site ID that configures SSO are the only admins who can manage SSO settings for all the organizations.

How Do I Change SSO Settings?

After you set up SSO with your IdP, you can view and manage details for the connection.

To change SSO settings:

  1. From Security, select Authentication.

  2. Under Authentication settings, select Manage SSO settings. On the page that appears, you can view and manage settings, such as the display name, claimed email domains, and the redirect URL.

However, some SSO settings can't be changed when an SSO connection is enabled. To edit these settings, you need to disable the connection. You can then set up the connection again and change the settings as necessary.

How Do I Change the IdP or Connection Method?

To change your IdP or connection method, you need to disable your connection, set up the connection again to make your changes, and then turn SSO back on. You also follow this process to change any other configuration settings, except for adding claimed email domains, which you can do without turning off SSO. For detailed instructions, see Set Up Single Sign-on (SSO).