- Home
- /
- Article
SAML Auto Account Creation and Update for Control Hub
You can use SAML to map user attributes from IdP to Webex identity attributes, and turn on just-in-time (JIT) auto account updates using SAML assertion.
Modify Single sign-on authentication in Control Hub
Before you begin
Ensure that the following preconditions are met:
-
SSO is already configured. For information on using the SSO configuration wizard, see Single Sign-On Integration in Control Hub.
-
The domains have already been verified.
-
The domains are claimed and turned on. This feature ensures users from your domain are created and updated once each time they authenticate with your IdP.
-
If DirSync or Entra ID are enabled then SAML JIT create or update will not work.
-
Block user profile update is enabled. SAML Update Mapping is allowed because this configuration controls the user’s ability to edit the attributes. Admin-controlled methods of creation and update are still supported.
Prevent users from self-registering with your domain must be enabled. SAML JIT account creation won’t work if this setting is disabled. For more information, see Prevent users from self-registering with your domain.
Newly created users won't automatically get assigned licenses unless the organization has an automatic license template set up.
User provisioning for SAML JIT provisioning of groups is limited to a single group only.
Configure Just-in-Time (JIT) and SAML mapping
| 1 |
Sign in to Control Hub. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 2 |
Go to . | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 3 |
Go to the Identity provider tab. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 4 |
Go to the IdP and click | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 5 |
Select Edit SAML mapping. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 6 |
Configure Just-in-Time (JIT) settings.
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 7 |
Configure SAML mapping required attributes.
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 8 |
Configure the Linking attributes. This should be unique to the user. It is used to lookup a user so that Webex can
update all profile attributes, including email for a user.
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 9 |
Configure Profile attributes.
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 10 |
Configure Group attributes.
If user A is associated with SAML JIT provisioning does not support the removal of users from groups or any deletion of users.
For a list of SAML assertion attributes for Webex Meetings, see SAML Assertion Attributes for Webex Meetings and Jabber. |
.