Unified SSO administration
Use single sign-on (SSO) to authenticate users in Bloomreach, then optionally use SSO authorization to manage roles and access through your identity provider.
What is single sign-on
SSO lets you sign in once and access multiple applications without entering your username and password again. It creates a trusted connection between your identity provider (IdP, the system that verifies your identity) and the applications you use. When you access another application, it checks with your IdP to confirm that you are already signed in. If your IdP verifies your identity, the application grants access immediately.
SSO authentication vs SSO authorization
SSO authentication and SSO authorization serve different purposes:
- SSO authentication: Verifies who you are through your company credentials.
- SSO authorization: Determines what you can access by controlling your permissions and roles in Bloomreach products.
You can use SSO authentication alone and assign user roles manually in Bloomreach. Enable SSO authorization to manage roles through your IdP.
SSO authentication
SSO authentication lets your employees use company credentials to access subscribed Bloomreach products with one sign-in. After authentication, they can move between products such as Marketing, Search, and other Bloomreach applications. You manage user permissions in the Bloomreach platform.
How SSO authentication works
Configure SSO as an additional sign-in method alongside email and social authentication, or as your organization's only authentication method. Unified Bloomreach SSO uses SAML 2.0 for authentication.
Authentication flow
- Users open the Bloomreach platform.
- They select SSO sign-in and enter their company credentials.
- The identity provider verifies their credentials.
- Users gain access to all subscribed Bloomreach products with their assigned permissions.
SSO authentication specifications
- User invitation: Users with SSO authorization do not require an invitation. Invite users without SSO authorization to the Bloomreach application.
- Role-assignment timing: SSO authorization assigns roles during sign-in. Role changes can take up to one minute to appear.
- Two-factor authentication (2FA) and multi-factor authentication (MFA): When users authenticate through SSO, Bloomreach 2FA and MFA do not apply. Your IdP manages MFA.
- Single provider per account: Each account can have only one SSO provider enabled.
- One SSO per user per instance: Each user can only be managed by one SSO application per instance.
SSO authorization
SSO authorization extends SSO authentication by managing user roles and provisioning through your IdP. It removes the need for manual invitations and permission assignments in Bloomreach. You control access rights in your IdP.
How SSO authorization works
SSO authorization uses role_mapping to connect IdP attributes to Bloomreach permissions. When users sign in through SSO, Bloomreach reads the role_mapping field sent by the IdP and assigns permissions from the matching mapping role.
Authorization flow
- The user authenticates through your IdP.
- The IdP sends a SAML assertion that includes a
role_mappingvalue. - Bloomreach matches the
role_mappingvalue to configured mapping roles. - Bloomreach assigns permissions based on the matched mapping role.
- If the user does not exist, Bloomreach creates the user with the assigned roles.
Role mapping values
The role_mapping field can contain:
- User profile fields (department, division, job title).
- User group memberships.
- Fixed string values.
- Multiple groups (sent as a list).
When SSO authorization is disabled
- Invite users manually to Bloomreach.
- Assign roles manually through account access management.
- Existing SSO users retain their manually assigned roles.
SSO authorization specifications
- SSO module required: Available only for accounts with the SSO module enabled.
- Native-account limitation: You can manage roles through SSO authorization only for native accounts (accounts registered with the IdP).
- External-account access: Manage access to accounts other than the native account (accounts not registered with the SSO provider) directly in Bloomreach.
- Role propagation delay: Changes take up to 60 seconds to propagate.
- Sign-in requirement: Role changes apply only when the user signs in.
- Access-management restrictions: When SSO is enabled, manage permissions in your IdP (for example, Microsoft Entra ID or Okta), not in Bloomreach. The Add permission button does not appear in the UI. Changes in your IdP take effect the next time the user signs in through SSO.
- Admin-only control: Only users with the SSO Admin role (Cloud Organization scope) can disable SSO authorization and manage mapping roles.
- Role mapping required before enabling: Create at least one role mapping before enabling SSO authorization. Otherwise, all users are blocked from signing in.
SSO configuration and next steps
Use the following SSO authentication and authorization guides:
- Unified SSO for Microsoft Entra ID (formerly Azure Active Directory)
- Unified SSO for Okta
- Unified SSO authorization for Microsoft Entra ID (formerly Azure Active Directory)
- Unified SSO authorization for Okta
For another identity provider, refer to that provider's documentation.
To manage SSO sign-in and user roles, see Unified SSO login and user management.
Updated 9 days ago

