Aller au contenu principal

Team SSO

Open My Account → Single Sign-On to attach this team's own SAML identity provider. You do not need a platform-wide SSO change from Automation Anywhere.

Only team admins can open this tab.

The header copy depends on whether the team has a subdomain:

  • With a subdomain: the default configuration is offered automatically to anyone signing in on that subdomain.
  • Without a subdomain: no configuration can be offered automatically — members sign in through the Login URL instead.

Single Sign-On empty state

Empty State​

If there is no configuration yet: No SSO configuration yet. Members sign in with the methods enabled for this team.

Use + Add configuration to create one. Refresh reloads the list.

Team SSO vs. Platform SSO​

Platform SSOTeam SSO
Who configuresTypically Super Admin / AA SupportTeam admin (and parent admins for descendants)
ScopeOrganization / instance-wide patternsOne team (and how members reach that team)
DocsSingle Sign-On (SSO)This page

Team SSO configurations live separately from the app-wide SSO path so they are not mixed up with platform providers.

Add a Configuration​

  1. Click Add Configuration

    The New SSO configuration form opens on the page.

  2. Fill in the Fields

    FieldDescription
    NameLabel shown on the sign-in button (for example Acme Okta)
    Metadata URLOptional IdP metadata URL. You can upload the metadata XML instead after creating the configuration.
    Offer this configuration on the team's subdomainOn only when the team has a subdomain and a metadata URL is set. Otherwise the control stays off — there is nowhere to offer it, or the sign-in button would fail.

    New SSO configuration

  3. Create

    Click Create. Cancel closes the form without saving.

You can keep multiple configurations per team (up to 20).

If this team is a sub-team, Copy from parent team appears. That makes an independent copy (new Entity ID and ACS URL). Register those values with your identity provider before anyone signs in. Later changes on the parent do not reach the copy.

After You Create a Configuration​

Copy these values into your IdP:

ValueUse
Entity ID (audience)SAML audience for this configuration
ACS URL (reply URL)Assertion Consumer Service / reply URL
Login URLWhere members start SSO when subdomain auto-offer is not in use

Each configuration gets its own ACS URL and audience so two teams pointing at the same IdP cannot replay one another's assertions.

You can then:

  • Edit Name and Metadata URL
  • Upload metadata XML (or Replace metadata XML)
  • Toggle Enabled
  • Use on this team's subdomain to make this the default (promoting one demotes the previous default)
  • Delete the configuration

Badges on a card can include Default, Disabled, Metadata missing, and Register with your IdP (after copying from a parent, until you register the new SP with the IdP).

Subdomain Behavior​

SituationWhat members see
Team has a subdomain and a default configThat IdP can be offered automatically on the subdomain
Team has no subdomainNo automatic offer — use the configuration's Login URL
Default marked but no subdomainThe card notes that a subdomain is required for the default offer to take effect

Subdomains for child teams are managed from Sub-teams.

Who Can Manage Team SSO​

ActorCan manage
Team AdminThis team's SSO
Parent Team AdminThis team and descendant teams' SSO
Super AdminAll teams (when acting with admin authority)
Editor / MemberNo