Troubleshooting Single Sign-On With the Admin Self-Recovery Option
This article describes the Admin Self-Recovery process for Control Hub if Single Sign-On (SSO) does not work.
Contributed by Josue Vizcaino, Cisco TAC Engineer
ISSUE
The single Sign-On certificate has expired, and you cannot access admin.webex.com, web.webex.com, or the Webex app.
RESOLUTION
The Self-Recovery option enables users to securely update or disable Single Sign-On using a protected backdoor API.
Self-Recovery via Admin Portal
- Open an incognito browser tab.
- Navigate to admin.webex.com/manage-sso.
- Enter the admin email and select Send One Time Password.
- A One Time Password (OTP) PIN will be sent from webex_comm@webex.com.
- Enter the OTP received and click the Sign In button.
- Choose one of the options below:
- Option 1: Disable SSO
- Option 2: Update the certificate and download metadata as needed.
Option 1: Disable SSO
- Select the toggle Modify your organization's SSO authentication.
- Confirm the action and select the Deactivate button.
- Single Sign-On is successfully disabled, and basic Webex authentication is in place.
Option 2: Update Certificate
- Choose a Certificate and upload the updated IdP Metadata file.
- Click the Test SSO setup button.
- Once Single Sign-On succeeds, it is safe to Sign Out from the Manage-SSO portal.
If Options 1 and 2 do not resolve the issue, don't hesitate to contact Cisco TAC for more help.
CAUSE
- IdP or SP certificate has expired.
- Misconfiguration in the Single Sign-On setup.
- Outage affecting Single Sign-On services.
Was this article helpful?