Skip to main content
Version: Version 22

Single Sign-On (SSO)

Fortes Change Cloud supports Single Sign-On (SSO). With SSO, employees log in once to access all connected systems. This increases security and ease of use.


How Does Single Sign-On Work?​

SSO is based on the concept of federated identity. Attributes are shared between trusted systems using protocols such as OpenID Connect and SAML 2.0.

When a user logs in, an authentication token is created and stored in the browser or on the SSO server. Any application the user opens afterwards consults the SSO service, which transmits the token to establish identity and grant access.

There are two types of providers:

  • Service Provider (SP): the systems and applications that users use throughout the day (e.g. Fortes Change Cloud).
  • Identity Provider (IdP): the system that performs user authentication and stores login credentials (e.g. Azure AD, Okta, ADFS).

Benefits of SSO​

  • Reduced attack surface: SSO eliminates poor password hygiene, making your organization less vulnerable to phishing attacks. Users only need to remember one strong, unique password.
  • Seamless and secure user access: SSO provides real-time visibility into which users are using applications, and when. IT teams can immediately disable access when a device is lost.
  • Easier control of user access: Configure access rights based on job title, department, or seniority. SSO solutions keep access levels transparent and consistent.
  • Independent and productive users: Employees get instant access to the applications they need without manual oversight or waiting for IT approval.
  • Future-proof: SSO is the foundation for implementing additional security best practices such as Two-Factor Authentication (2FA).

Risk​

Once a user is logged in via SSO, they can access all connected systems. It is strongly recommended to combine SSO with an additional level of authentication.


SSO and Two-Factor Authentication (2FA)​

For logging into Fortes Change Cloud, Two-Factor Authentication (2FA) is recommended. When 2FA is enabled at the Identity Provider level, every linked application is also protected. This adds an additional security layer to your landscape.


Setting Up Single Sign-On​

To use SSO, the Identity Provider must be able to communicate with Fortes Change Cloud. Configuration is required on both sides: in Fortes Change Cloud and at the Identity Provider.

Supported Protocols​

Fortes Change Cloud supports the following protocols:

  • Security Assertion Markup Language (SAML): One of the most widely used standards for exchanging authentication data. All products that use SAML can interface with Fortes Change Cloud. Examples: ADFS, Okta, Azure AD, SURFconext, Shibboleth, OpenAM/OpenSSO, GlobalSign.
  • Shibboleth (SP): An implementation of SAML that uses OpenSAML to provide SAML functionality.

Registration Steps​

  1. Register Fortes Change Cloud as a trusted application at the Identity Provider.
  2. Provide the following details to the Identity Provider:
    • Name: The name of the application.
    • Domain: The (sub)domain on which the application runs.
    • Redirect URI: The location within Fortes Change Cloud where the user is sent after logging in. Example: https://mycompany.fortes-online.com
  3. Obtain the metadata file or federation URL from the Identity Provider.

Note: The Service Provider needs a metadata file or the federation URL from the Identity Provider. Contact support@fortes.nl for assistance.

Identity Provider Documentation​

ProviderDocumentation Link
ADFShttps://docs.microsoft.com/en-us/windows-server/identity/active-directory-federation-services
Oktahttps://help.okta.com/en/prod/Content/Topics/Apps/Apps_Overview_of_Managing_Apps_and_SSO.htm
Azure ADhttps://docs.microsoft.com/nl-nl/azure/active-directory/saas-apps/fortes-change-cloud-tutorial
SURFconexthttps://wiki.surfnet.nl/display/surfconextdev/SAML+Basics

Creating and Migrating Users​

Fortes Change Cloud offers two options for creating new users and migrating existing users:

Manually Create or Update Users​

When SSO is used, the match is done on a unique identifier. The user should be identical on both the Identity Provider and Service Provider side. You can:

  • Enter user data manually in the User Manager.
  • Import users once via an import task as resources, then upgrade them to resources with a username.

Automatically Create or Update Users​

Automatic user synchronization is also available. When this setting is enabled, the administrator at the Identity Provider can mark users to use SSO in conjunction with automatic synchronization via the SCIM protocol.


FAQ​

Q: Does enabling SSO have additional costs? A: No. There are no additional costs associated with enabling SSO. Contact support@fortes.nl to get started.

Q: Can I use both SAML and Shibboleth? A: Shibboleth is an implementation of SAML, so they are compatible. You can use whichever your Identity Provider supports.


Support​

For questions about setting up SSO, contact support@fortes.nl.