Skip to main content

Configure single sign-on with SAML

We recommend keeping two browser tabs open: one for DigiCert​​®​​ account and another for your identity provider (IdP). This setup allows you to easily reference both platforms and complete Security Assertion Markup Language (SAML) 2.0 configuration without interruptions.

Prerequisites

Before configuring SAML in DigiCert​​®​​ account:

  • Have administrator access to your company's IdP service, such as Microsoft Entra, Okta, Google Workspace, or other user management service.

  • Make sure authentication from your IdP signs the response and the assertion.

  • Have your IdP metadata and SAML certificate.

Set up SSO with SAML

  1. In DigiCert​​®​​ account, select the Accounts icon > sign in methods.

  2. Select Single-Sign-On with SAML.

  3. In the Connect DigiCert to your IdP section, select Download DigiCert metadata.

    Where do I upload DigiCert metadata in my IdP?

  4. In the Connect your IdP to DigiCert section, select Upload IdP metadata.

    Where do I download my IdP metadata?

  5. When both steps are finished, in the Enable/Disable SSO with SAML section, switch to enable SSO with SAML.

  6. Select Save configuration.

Troubleshooting

To configure SSO with SAML, you need to create a SAML application for DigiCert​​®​​ account in your IdP. During the process of creating this application, you need to provide DigiCert's metadata. When the application is created, you can download your IdP metadata that you need to provide to DigiCert​​®​​ account.

Dica

To perform this action, you must be an admin in your IdP.

Select your IdP:

Select your IdP:

Select your IdP:

Select your IdP:

Two-factor authentication and SSO with SAML

When 2FA is enabled, DigiCert prompts you to enter an OTP when signing in, even if you have already provided an OTP to your identity provider (IdP).