Skip to main content

SSO Integration Instructions

These instructions allow you to configure the watchTowr Platform to leverage any SAML-based SSO provider.

Updated this week

Overview

watchTowr supports Single Sign-On (SSO) integration with any SAML-based identity provider (IdP), allowing organizations to centralize user authentication and streamline secure access management.

This documentation provides step-by-step instructions for:

Setting Up SSO

  1. Navigate to Platform > Users > Set up SSO.

  2. Choose the SSO provider you want to configure. You can choose to configure any SAML integration or leverage specific SSO provider presets such as:

    • Microsoft Entra ID

    • Google Workspace

    • Okta

    • OneLogin

  3. Click Continue.

  4. Copy Identifier (Entity ID) and Reply URL (Assertion Consumer Service URL) to configure your SSO provider.

  5. Enter SSO Login URL and upload X.509 Certificate.

  6. Click Continue once you have entered all required information.

  7. Click Verify to test the connection. (Return to this window to confirm the status.)

  8. A new window will open to test the connection.

    1. You will be logged in and redirected to the Platform (Security Posture Dashboard) if SSO setup was successful. Navigate back to the old window and click Yes, enable for all.

    2. If unsuccessful, navigate back to the old window and click No, speak to support.

  9. Once you have clicked Yes, enable for all, you will see a message confirming that SSO has been enabled. The SAML Single Sign-On status will also appear as Enabled.

Please note that Email/Password login will be disabled once SSO is enabled.

Disabling SSO

  1. Navigate to Platform > Users.

  2. Click Delete under SAML Single Sign-On.

  3. Click Disable.

  4. You will see a message confirming that SAML SSO has been disabled.

Renewing SSO Certificate

Users will receive a series of automated notification emails as your organisation's SSO certificate approaches its expiry date. These reminders are sent 30 days, 14 days, 7 days, and 1 day before the certificate expires.

To ensure uninterrupted SSO access for your organization, please renew your SSO certificate before the expiry date. Failure to renew the certificate will result in users being unable to authenticate via SSO.

To renew your SSO Certificate,

  1. Navigate to Platform > Users.

  2. Click Renew under SAML Single Sign-On to update the certificate in your watchTowr Platform SSO settings.

  3. Upload valid X.509 Certificate and click Renew.

If you need assistance, don't hesitate to contact the watchTowr team. Our knowledgeable team is ready to help you navigate the watchTowr Platform and address any questions or concerns.

Did this answer your question?