Unified SSO administration

Use single sign-on (SSO) to authenticate users in Bloomreach, then optionally use SSO authorization to manage roles and access through your identity provider.

What is single sign-on

SSO lets you sign in once and access multiple applications without entering your username and password again. It creates a trusted connection between your identity provider (IdP, the system that verifies your identity) and the applications you use. When you access another application, it checks with your IdP to confirm that you are already signed in. If your IdP verifies your identity, the application grants access immediately.

SSO authentication vs SSO authorization

SSO authentication and SSO authorization serve different purposes:

  • SSO authentication: Verifies who you are through your company credentials.
  • SSO authorization: Determines what you can access by controlling your permissions and roles in Bloomreach products.

You can use SSO authentication alone and assign user roles manually in Bloomreach. Enable SSO authorization to manage roles through your IdP.

SSO authentication

SSO authentication lets your employees use company credentials to access subscribed Bloomreach products with one sign-in. After authentication, they can move between products such as Marketing, Search, and other Bloomreach applications. You manage user permissions in the Bloomreach platform.

How SSO authentication works

Configure SSO as an additional sign-in method alongside email and social authentication, or as your organization's only authentication method. Unified Bloomreach SSO uses SAML 2.0 for authentication.

Authentication flow

  1. Users open the Bloomreach platform.
  2. They select SSO sign-in and enter their company credentials.
  3. The identity provider verifies their credentials.
  4. Users gain access to all subscribed Bloomreach products with their assigned permissions.

SSO authentication specifications

  • User invitation: Users with SSO authorization do not require an invitation. Invite users without SSO authorization to the Bloomreach application.
  • Role-assignment timing: SSO authorization assigns roles during sign-in. Role changes can take up to one minute to appear.
  • Two-factor authentication (2FA) and multi-factor authentication (MFA): When users authenticate through SSO, Bloomreach 2FA and MFA do not apply. Your IdP manages MFA.
  • Single provider per account: Each account can have only one SSO provider enabled.
  • One SSO per user per instance: Each user can only be managed by one SSO application per instance.

SSO authorization

SSO authorization extends SSO authentication by managing user roles and provisioning through your IdP. It removes the need for manual invitations and permission assignments in Bloomreach. You control access rights in your IdP.

How SSO authorization works

SSO authorization uses role_mapping to connect IdP attributes to Bloomreach permissions. When users sign in through SSO, Bloomreach reads the role_mapping field sent by the IdP and assigns permissions from the matching mapping role.

Authorization flow

  1. The user authenticates through your IdP.
  2. The IdP sends a SAML assertion that includes a role_mapping value.
  3. Bloomreach matches the role_mapping value to configured mapping roles.
  4. Bloomreach assigns permissions based on the matched mapping role.
  5. If the user does not exist, Bloomreach creates the user with the assigned roles.

Role mapping values

The role_mapping field can contain:

  • User profile fields (department, division, job title).
  • User group memberships.
  • Fixed string values.
  • Multiple groups (sent as a list).

When SSO authorization is disabled

  • Invite users manually to Bloomreach.
  • Assign roles manually through account access management.
  • Existing SSO users retain their manually assigned roles.

SSO authorization specifications

  • SSO module required: Available only for accounts with the SSO module enabled.
  • Native-account limitation: You can manage roles through SSO authorization only for native accounts (accounts registered with the IdP).
  • External-account access: Manage access to accounts other than the native account (accounts not registered with the SSO provider) directly in Bloomreach.
  • Role propagation delay: Changes take up to 60 seconds to propagate.
  • Sign-in requirement: Role changes apply only when the user signs in.
  • Access-management restrictions: When SSO is enabled, manage permissions in your IdP (for example, Microsoft Entra ID or Okta), not in Bloomreach. The Add permission button does not appear in the UI. Changes in your IdP take effect the next time the user signs in through SSO.
  • Admin-only control: Only users with the SSO Admin role (Cloud Organization scope) can disable SSO authorization and manage mapping roles.
  • Role mapping required before enabling: Create at least one role mapping before enabling SSO authorization. Otherwise, all users are blocked from signing in.

SSO configuration and next steps

Use the following SSO authentication and authorization guides:

For another identity provider, refer to that provider's documentation.

To manage SSO sign-in and user roles, see Unified SSO login and user management.


Did this page help you?

© Bloomreach, Inc. All rights reserved.