Translate to:
Please select
  • English (English)
  • French (Français)
  • German (Deutsch)
  • Indonesian (Bahasa Indonesia)
  • Italian (Italiano)
  • Portuguese (Português)
  • Russian (Русский)
  • Spanish (Español)
  • Thai (ไทย)
  • Turkish (Türkçe)
  • Vietnamese (Tiếng Việt)
Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Notifications
Login / Register
Community
Community
Notifications
close
  • Forums
  • Knowledge Center
  • Events & Webinars
  • Ideas
  • Blogs
Help
Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Login / Register
Sustainability
Sustainability

We Value Your Feedback!
Could you please spare a few minutes to share your thoughts on Cloud Connected vs On-Premise Services. Your feedback can help us shape the future of services.
Learn more about the survey or Click here to Launch the survey
Schneider Electric Services Innovation Team!

Configure SAML single sign on (SSO) in IT Expert

Single Sign On (SSO)

How to configure SAML Single Sign On (SSO) in EcoStruxure IT Expert

Enter a search word
    Turn off suggestions
    Enter a search word
      Turn off suggestions
      Enter a user name or rank
        Turn off suggestions
        Enter a search word
          Turn off suggestions
          Enter a search word
            Turn off suggestions
            cancel
            Turn on suggestions
            Showing results for 
            Show  only  | Search instead for 
            Did you mean: 
            Important Note
            • Home
            • Schneider Electric Community
            • EcoStruxure IT Help Center
            • EcoStruxure IT Help Center Categories
            • IT Expert
            • Configuration
            • Single Sign On (SSO)
            • Configure SAML single sign on (SSO) in IT Expert
            Options
            • Mark as New
            • Mark as Read
            • Bookmark
            • Subscribe
            • Email to a Friend
            • Printer Friendly Page
            • Report Inappropriate Content
            Invite a Co-worker
            Send a co-worker an invite to the portal.Just enter their email address and we'll connect them to register. After joining, they will belong to the same company.
            You have entered an invalid email address. Please re-enter the email address.
            This co-worker has already been invited to the Exchange portal. Please invite another co-worker.
            Please enter email address
            Send Invite Cancel
            Invitation Sent
            Your invitation was sent.Thanks for sharing Exchange with your co-worker.
            Send New Invite Close

            Related Forums

            • EcoStruxure IT forum

            • APC UPS Data Center & Enterprise Solutions Forum

            Previous Next

            Invite a Colleague

            Found this content useful? Share it with a Colleague!

            Invite a Colleague Invite

            EcoStruxure IT Support

            Submit a support request for additional assistance with EcoStruxure IT software.

            Request Support
            Back to Single Sign On (SSO)
            Options
            • Mark as New
            • Mark as Read
            • Bookmark
            • Subscribe
            • Email to a Friend
            • Printer Friendly Page
            • Report Inappropriate Content
            1 Like
            9542 Views

            Link copied. Please paste this link to share this article on your social media post.

            Trying to translate this page to your language?
            Select your language from the translate dropdown in the upper right. arrow
            Translate to: English
            • (Français) French
            • (Deutsche) German
            • (Italiano) Italian
            • (Português) Portuguese
            • (Русский) Russian
            • (Español) Spanish

            Configure SAML single sign on (SSO) in IT Expert

            Picard EcoStruxureIT
            ‎2021-06-23 11:39 PM

            Last Updated: Sisko JLehr Sisko ‎2025-02-18 08:46 AM

            Administrator users and partners can configure SAML 2.0 single sign on in the Administration > More > SSO option in IT Expert. Any identity provider (IdP) that supports the SAML protocol is supported. 

            An EcoStruxure IT Expert subscription is required.

             

            Once you configure SSO, all users with an email address on one of the domains you specify must use your identity provider to log in to IT Expert.

             

            You can still use the IT Expert Administration > Users option to invite and manage users from email domains not using the domains you specify for SSO.

             

            If your SSO certificate expires, you must reset your SSO configuration.

             

            idea_icon_4403017628561.pngidea_icon_4403017628561.png

             

            It is strongly recommended that at least one Administrator user who does not require SSO to log in is configured in IT Expert Administration > Users.

             

            If you subscribe devices to EcoStruxure Asset Advisor and configure SSO, you must also configure your organization's users on the Administration > Users tab. Otherwise, the Schneider Electric Service Bureau cannot contact the individuals responsible in case of an incident.

             

             

            In this article

            • Configure your identity provider
            • Supported SAML attributes
            • Configure SSO in IT Expert
              • 1. Enter SAML details
              • 2. Test SAML configuration
              • 3. Verify domain ownership
              • Enable Identity Provider (idP) Initiated SSO login
            • Update your SAML SSO certificate or sign-in URL
            • Reset SSO configuration

             

            Configure your identity provider

             

            Azure users also see Configure Azure AD for IT Expert SAML SSO

             

            Before you configure SSO in IT Expert, use the Identity Provider details on the Administration > More > SSO page to configure the integration with IT Expert in your identity provider's user interface.

            Refer to your identity provider's documentation for more information.

             

            ITE SAML identity provider details.png

             

            1. Log in to IT Expert and go to Administration > More > SSO.

               

            2. Copy and paste the SAML Assertion Consumer Service (ACS) URL and the SP Entity ID in the appropriate fields. These values are specific to your account.

              Note: The SP Metadata URL will be displayed in step 2 of the IT Expert configuration. Some identity providers require it.

               

            3. IT Expert requires that you configure your identity provider to send these three SAML attributes:

               

                  • "name": How user names are displayed
                  • "email": User email address
                  • "groups": The groups your IT Expert users are members of
                    Note: Groups configuration is not applicable for partners.

                     

            If your identity provider does not support adding the SAML attributes above, see the full list of supported SAML attributes below to use as alternatives.

             

            You can create groups in both your identity provider and IT Expert; group names must match exactly in both. You can assign access permission for each group on the IT Expert Administration > Groups tab. See IT Expert permissions

             

            Note: IT Expert contains two groups by default, Administrators and Users.

            Users you want to have Administrator rights in ITE must have a group SAML attribute with the value "Administrators."  Users who should have regular user rights in ITE must have a group SAML attribute with the value "Users." Users without a group SAML attribute will not have access to ITE. 

            Consult the documentation for your identity provider to learn about adding SAML attributes.

             

            Note: Every time a user logs in using SSO, the identity provider sends EcoStruxure IT a list of the groups the user belongs to. If any changes to group assignments are needed, you make the changes in your identity provider, not in IT Expert.

             

            Supported SAML attributes

             

            EcoStruxure IT supports these attributes, if, for example, your identity provider only supports InCommon Federation Attributes, or other standard attributes:

             

            SAML attribute

            Description

            name

            Display name of the user

            displayname

            urn:oid:2.16.840.1.113730.3.1.241

            http://schemas.microsoft.com/identity/claims/displayname

            http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name

            email

            E-mail address of the user

            urn:oid:0.9.2342.19200300.100.1.3

            http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress

            phone

            Phone number of the user

            phoneNumber

            telephoneNumber

            urn:oid:2.5.4.20

            urn:oid:0.9.2342.19200300.100.1.20

            urn:oid:0.9.2342.19200300.100.1.41

            http://schemas.xmlsoap.org/ws/2005/05/identity/claims/mobilephone

            group

            List of groups the user is a member of

            groups

            urn:oid:2.16.840.1.113719.1.1.4.1.25

            http://schemas.xmlsoap.org/claims/Group

             

            Configure SSO in IT Expert

            Your identity provider will provide the information needed to configure SSO in IT Expert.

            Return to IT Expert Administration > More... > SSO.

             

            1. Enter SAML details

             

            ITE SAML details.png

             

            1. Copy the SAML SSO sign-in URL from your identity provider into the SAML SSO sign-in URL field.

              In Azure, this is the User access URL under Properties.

              The URL must start with https://

               

            2. Upload your SAML SSO certificate or paste it into the text field. The certificate must be x.509 in *.PEM or *.CER format.

               

              The certificate must start with:
               ‘-----BEGIN CERTIFICATE-----’
              and end with:
              ‘-----END CERTIFICATE-----’ 

               

              Make sure there are no blank lines before or afterThe certificate expiration date is automatically extracted from the valid certificate and cannot be edited.

               

            3. Specify your Sign-in email domain(s). For example, if user email addresses are user@mydomain.com, enter mydomain.com in the field.

              Separate multiple domains with a comma, or use the Enter or Tab keys.

              Note: All users with an email address on one of the domains you specify must use your identity provider to log in to IT Expert.

              ITE SAML email domain.png

            The Continue button is enabled when all the field are populated and valid.

             

            2. Test SAML configuration

            Verify that your SAML connection is configured properly. 

             

            ITE SAML test configuration.png

             

            1. Open a different browser or an incognito window.

               

            2. Go to https://ecostruxureit.com and click Log in. Choose Customer. 

               

            3. Enter the test email address shown in ITE. 

              The password field will disappear, and the login for your identity provider will be displayed.

               

            4. Log in to EcoStruxure IT as Administrator.

               

            5. Return to SSO configuration in ITE. If the test login was successful, click Verify.
              If the test login was not successful, the SAML configuration is incorrect. Click Not working? Start again.

               

            IMPORTANT: You must successfully test your connection to enable SSO for your email domains.

             

            3. Verify domain ownership

             

            You must verify that you own the domains you specified in the SAML details. There are three ways to verify ownership: DNS TXT, HTML file, or HTML META. The verification method you choose depends on your domain's web host. 

             

            Contact your Customer Success Manager for help verifying your domain ownership if needed.

             

            DNS

             

            1. Go to the home page of your domain and create a DNS TXT record.

               

            2. Copy the TXT content displayed in ITE starting with ecostruxure-it-verification=

               

            3. Return to ITE and click Verify. A checkmark icon ITE SAML domain verified icon.png appears next to verified domains.  

               

              ITE SAML verify domain.png

             

            HTML file

             

            1. Create the file ecostruxure-it-verification.html using the contents diplayed in ITE, and upload it to your domain's website. 
              Your website must be publicly available at the naked domain, with no www or any other subdomain prefix in its URL. Example: https://randomdomain.dk/ecostruxure-it-verification.html 

               

            2. Return to ITE and click Verify.

               

              ITE SAML verify domain HTML.png

               

            HTML META

             

            1. Add the meta tag displayed in ITE to the <head> section of your website's home page.
              Your website must be publicly available at the naked domain, with no www or any other subdomain prefix in its URL. Example:

               

              https://randomdomain.dk/ecostruxure-it-verification.html

               

            2. Return to ITE and click Verify.

               

              ITE SAML verify domain HTML META.png

             

            Repeat step 3 to verify all the domains you specified.

             

            Once you have verified all your domains, your SSO configuration is complete. You can return to the SSO page to add and verify additional domains as necessary.

             

            You can remove unverified domains at any time. You can remove verified domains as long as at least one verified domain is configured.

             

            ITE SAML domain details 3.png

            Enable Identity Provider (IdP) Initiated SSO login

             

            Check to allow users to log in to IT Expert from the login page for your organization's identity provider. 
            Note: IT Expert uses OIDC as a response protocol.

            See Identity Provider (IdP) initiated SSO risks and considerations

             

             

            Edit configuration

             

            Click Edit configuration to update your SAML SSO sign-in URL or SAML SSO certificate.

             

            Note: Edit mode is available only when there is at least one Administrator user configured in IT Expert who does not required SSO to log in.

            You can jump between configuration steps when in edit mode.

             

            Click Yes to continue.

             

            ITE SAML warning message.png

             

            Update your SAML SSO sign-in URL and SAML SSO certificate as needed.

            The expiration date is extracted from the certificate and cannot be edited.

            Click Continue.

             

            ITE SAML details 2.png

             

             

            Click Cancel Edit if you decide not to make changes at this time or you make a mistake.

             

            Test your SAML configuration (see step 2 above) and then verify your domain (see step 3 above) to enable SAML SSO settings.

             

            Reset SSO configuration

             

            Resetting your SSO configuration completely removes all SSO settings in IT Expert.

             

            You must start again at step 1 to reconfigure SSO, including reconfiguring SSO when your SSO certificate has expired.

            The URLs and verification files from any previous ITE SSO configuration cannot be reused.

             

            When you reset your SSO configuration, users who are required to use SSO to log in to ITE will no longer have access unless they also have IT Expert user accounts listed in Administration > Users.

             

            Was this article helpful? Yes No
            100% helpful (1/1)

            Link copied. Please paste this link to share this article on your social media post.

            Comments
            maxstr
            maxstr
            Cadet
            • Mark as Read
            • Mark as New
            • Bookmark
            • Permalink
            • Print
            • Email to a Friend
            • Report Inappropriate Content
            ‎2024-11-26 11:24 AM

            When adding the certificate, I downloaded the PEM file directly from Azure, but it kept saying invalid certificate. I figured out I had to delete the last line for it to be accepted. For example, after the part that says "-----END CERTIFICATE-----", there was a blank line below it that I needed to delete. 

             

            Schneider should automatically trim empty lines because those certificates have a blank line by default

            JLehr
            Sisko JLehr Sisko
            Sisko
            • Mark as Read
            • Mark as New
            • Bookmark
            • Permalink
            • Print
            • Email to a Friend
            • Report Inappropriate Content
            ‎2024-12-02 08:47 AM

            Hi @maxstr,

             

            Thanks for the feedback. I'll pass it along.

             

            You can provide feedback directly in the IT Expert application, too. Click the Help icon (?) in the upper right corner and then click Feedback.

            JLehr_0-1733157977861.png

             

            JLehr
            Sisko JLehr Sisko
            Sisko
            • Mark as Read
            • Mark as New
            • Bookmark
            • Permalink
            • Print
            • Email to a Friend
            • Report Inappropriate Content
            ‎2024-12-03 06:22 AM

            Hi @maxstr,

             

            Thanks again for pointing out the spacing issue in the certificate. Engineering will address it shortly.

             

            Best,

             

            Jackie

             

             

            Kenny_Roach
            Kenny_Roach
            Cadet
            • Mark as Read
            • Mark as New
            • Bookmark
            • Permalink
            • Print
            • Email to a Friend
            • Report Inappropriate Content
            ‎2025-05-29 12:25 PM

            After adding the DNS TXT records and successfully verifying the domains, can the DNS TXT files be deleted?

            JLehr
            Sisko JLehr Sisko
            Sisko
            • Mark as Read
            • Mark as New
            • Bookmark
            • Permalink
            • Print
            • Email to a Friend
            • Report Inappropriate Content
            ‎2025-06-04 05:39 AM

            Hi @Kenny_Roach,

             

            Deleting the DNS TXT record won't affect SSO logins once you have verified the domain. If you delete it and you need to verify the domain again in the future, you'll have to add that TXT entry again into your DNS.

            Didn't find what you are looking for? Ask our Experts
            To The Top!

            Forums

            • APC UPS Data Center Backup Solutions
            • EcoStruxure IT
            • EcoStruxure Geo SCADA Expert
            • Metering & Power Quality
            • Schneider Electric Wiser

            Knowledge Center

            Events & webinars

            Ideas

            Blogs

            Get Started

            • Ask the Community
            • Community Guidelines
            • Community User Guide
            • How-To & Best Practice
            • Experts Leaderboard
            • Contact Support
            Brand-Logo
            Welcome to Schneider Electric Community!
            Forum-Icon

            You have two options to continue your visit.

            LOGIN / Register

            Why logging in?
            • You enable the complete set of features available, such as posting, sharing, subscribing, private messaging and more.
            • You unlock the access to the whole content that Schneider Electric Community has to offer, including the gated items and the special events.
            And it’s free of charge!!!

            OR

            Continue as a guest

            Terms & Conditions Privacy Notice Change your Cookie Settings © 2025 Schneider Electric

            This is a heading

            With achievable small steps, users progress and continually feel satisfaction in task accomplishment.

            Usetiful Onboarding Checklist remembers the progress of every user, allowing them to take bite-sized journeys and continue where they left.

            of

            Translating the page…
            The page is currently translating. Please wait.
            Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.