SAML / SSO - Setup guide
What is SSO
Single sign-on is an authentication solution allowing users to sign in to multiple systems using one set of credentials, companies benefit from this authentication scheme for multiple reasons including but not exclusive to,
Security
Time management
User experience
Benefits of using SSO
When using SSO, External Share will allow users to securely create and access accounts with minimum required credentials. Thanks to the use of a federated data system, it is possible to tighten security while making it convenient for users to access data.
Managing multiple SSO configurations
External Share supports multiple SSO/SAML configurations. This allows admins to integrate various identity providers (IdPs) and provide flexible authentication options depending on the workspace or specific sharing needs.
Global SSO Management: Create, edit, and manage multiple SSO configurations from the Global Settings sidebar.
Space-Specific SSO: Assign specific SSO configurations to individual Confluence spaces via Space Configuration.
Flexible External Share Authentication: When creating an external share, users can select suitable SSO configuration to authenticate end-users.
How to enable SSO on External Share
Navigate to Global Settings > SSO Configuration tab.
Click Create New Configuration and provide your Identity Provider (IdP) details, including metadata and domains.
(Optional) Go to Spaces Configuration to restrict which SSO options are available for specific spaces.
When creating a shared link, enable SAML/SSO under security settings and select the desired configuration from the picker.
If you are using a different identity provider, visit this page for general guide.
Require Corporate SSO login to access shared pages
After setting up the SSO, you may secure your shared pages by requiring external users to log in with single sign-on to access the page. This is especially useful when you share your Confluence content with coworkers that don’t have access to Confluence and you want to ensure that no information will leak outside your organization.
This option can be set on global and space levels as well as for a specific page.
Setting SSO Enforcement Levels
Require SSO login globally
Navigate to global settings:
Click on the “Apps” dropdown menu.
Select the “External Share”.
Click on Space configuration tab
Click on the “Edit default configuration” button
Select the “Security tab”
Select Optional or Required and Save
Require SSO login for a specific Space
Enter the Space
On the sidebar menu select the External Share option
Navigate to Space configuration
Security tab
Require Cooperate SSO login
Save
Please ensure the SSO login is set to optional on Global settings.
Require SSO for a specific page
Open the page
Click on the “External Share” button located on the top right corner of the page
Click on the “Create External Share link”
Navigate to the security tab
require Cooperate SSO Login
Please ensure the SSO login is set to optional on Space and Global settings.
You can also require SSO for multiple Spaces by creating new global configuration.