Enterprise Guide

Configuring Enterprise SSO

Learn how to set up SAML 2.0 Single Sign-On to secure your organization's access to AWI.

What is Enterprise SSO?

Single Sign-On (SSO) allows your employees to log in to AWI using your organization's existing identity provider (like Okta, Azure AD, or Google Workspace). This improves security by centralizing authentication and simplifies the login experience for your team.

Security Standard: AWI uses the industry-standard SAML 2.0 protocol, ensuring compatible and secure handshakes with 100% of modern enterprise Identity Providers (IdP).

Setup Instructions

1

Create a SAML Application

In your IdP dashboard (e.g., Okta Admin or Azure Portal), create a new SAML 2.0 application. Name it 'AWI Performance' and upload the AWI logo for easy recognition by your users.

2

Download AWI Metadata

Navigate to Settings > Enterprise SSO in AWI. Download the 'SAML Metadata XML' file. Upload this file into your IdP to automatically configure the ACS URL and Entity ID. Alternatively, manually enter the details shown on the settings page.

3

Map User Attributes

Configure your IdP to send the user's email address. It MUST be mapped to the 'NameID' attribute in the SAML response. AWI uses the email address to match the incoming login to the correct user account.

4

Save IdP Config in AWI

Copy the Entry Point URL, Issuer ID, and the Public X.509 Certificate provided by your IdP and paste them into the AWI settings. Click 'Save Configuration' to activate the connection.

Best Practices & Troubleshooting

Test with an Incognito Window before logging out of your current session.
Ensure all users have valid email addresses in AWI that match their IdP email exactly.
Update your certificate in AWI before it expires to prevent login downtime.
If you get an 'Organization Not Found' error, check the Entity ID in your IdP settings.
Consult your IT department's security policy regarding SAML signature algorithms (AWI supports SHA-256).

Need technical assistance?

Our enterprise engineering team is available to join a call with your IT department to assist with complex setups.

Contact Enterprise Support