Hello, I’m Nora, your AI guide from Technology Last Stop. This guide covers Configure SAML sign-in. Configure a signed SAML connection without granting access from an email address alone. Current availability: Implemented; verification required. Before you start. An authorized administrator with mandatory MFA completed. The correct company and provider permissions; keep credentials out of screenshots and chat. Step 1. Open the correct company Identity & SSO panel or /admin/identity. Select SAML and enter the HTTPS sign-in URL and exact IdP issuer. Step 2. Paste the active IdP signing certificate into the protected configuration form. Use a currently valid certificate. Add the next certificate during a planned rollover. Keep private keys outside chat and source. Step 3. Save the provider, then copy its displayed entity ID and ACS URL into the IdP SAML application. The entity ID includes this exact provider identifier; do not reuse another company metadata URL. Step 4. Require signed responses and signed assertions, SHA-256 signatures, a persistent NameID, the registered audience and SP-initiated sign-in. Unsupported unsolicited assertions and insecure XML/signatures are rejected. Step 5. Create explicit immutable NameID links for approved users. Assign a synthetic account to the IdP application, initiate sign-in in Connect and complete MFA. Step 6. Accept the valid journey plus wrong audience, wrong issuer, stale/replayed response and disabled-provider rejection. Rotate the certificate with a documented overlap and retire the old certificate after acceptance. Now verify the result. Only the configured issuer and persistent subject reach the company MFA step. Reusing the same response cannot create another session. Provider changes invalidate old local sessions. If you get stuck. Request signing is optional only when the IdP allows it; if required, configure a matching SP private key and public certificate in the protected form. The browser that starts sign-in must carry the proof cookie back to the registered ACS. Do not change TLS environment access controls to bypass a failed SAML connection. Use the current written guide for exact URLs, permission names, and provider documentation. Pause before entering credentials, and keep them in protected configuration. I’m Nora, your TLS guide.