SAML / SSO - Setup guide

SAML / SSO - Setup guide

What is SSO

Single sign-on is an authentication solution allowing users to sign in to multiple systems using one set of credentials, companies benefit from this authentication scheme for multiple reasons including but not exclusive to,

  • Security

  • Time management

  • User experience

Benefits of using SSO

When using SSO, External Share will allow users to securely create and access accounts with minimum required credentials. Thanks to the use of a federated data system, it is possible to tighten security while making it convenient for users to access data.

Managing multiple SSO configurations

External Share supports multiple SSO/SAML configurations. This allows admins to integrate various identity providers (IdPs) and provide flexible authentication options depending on the workspace or specific sharing needs.

  • Global SSO Management: Create, edit, and manage multiple SSO configurations from the Global Settings sidebar.

  • Space-Specific SSO: Assign specific SSO configurations to individual Confluence spaces via Space Configuration.

  • Flexible External Share Authentication: When creating an external share, users can select suitable SSO configuration to authenticate end-users.

How to enable SSO on External Share

  1. Navigate to Global Settings > SSO Configuration tab.

  2. Click Create New Configuration and provide your Identity Provider (IdP) details, including metadata and domains.

  3. (Optional) Go to Spaces Configuration to restrict which SSO options are available for specific spaces.

  4. When creating a shared link, enable SAML/SSO under security settings and select the desired configuration from the picker.

Here are examples of 2 Identity providers and how to set up for External Share,

  • Azure

  • Okta

If you are using a different identity provider, visit this page for general guide.

Require Corporate SSO login to access shared pages

After setting up the SSO, you may secure your shared pages by requiring external users to log in with single sign-on to access the page. This is especially useful when you share your Confluence content with coworkers that don’t have access to Confluence and you want to ensure that no information will leak outside your organization.

This option can be set on global and space levels as well as for a specific page.


Setting SSO Enforcement Levels

Require SSO login globally

Navigate to global settings:

  1. Click on the “Apps” dropdown menu.

  2. Select the “External Share”.

  3. Click on Space configuration tab

  4. Click on the “Edit default configuration” button

Frame 74.png
  1. Select the “Security tab”

  2. Select Optional or Required and Save

Frame 76.png

Require SSO login for a specific Space

  1. Enter the Space

  2. On the sidebar menu select the External Share option

  3. Navigate to Space configuration

  4. Security tab

  5. Require Cooperate SSO login

  6. Save

Frame 75.png

 

Please ensure the SSO login is set to optional on Global settings.

Require SSO for a specific page

  1. Open the page

  2. Click on the “External Share” button located on the top right corner of the page

  3. Click on the “Create External Share link”

  4. Navigate to the security tab

  5. require Cooperate SSO Login

image-20260313-131131.png

Please ensure the SSO login is set to optional on Space and Global settings.

You can also require SSO for multiple Spaces by creating new global configuration.