Self-Service Dashboard for Inbound SAML SSO Connections
This release introduces a fully self-service dashboard that lets customer administrators create, configure, and manage inbound SAML SSO connections end-to-end without depending on support teams or external partners. From a single landing page, admins can view all active and deleted connections, restore connections, manage certificates and metadata, and enable advanced features. Supported features include user provisioning, encryption, e-signature, and Learning Reporter.
What's New
- Create, update, delete, and restore inbound SAML SSO connections from a single self-service dashboard.
- Centralized landing page with a grid view of all active and deleted connections, including type, ID, status, creator, creation date, and last-used timestamp.
- Filter connections by status and creation date, with pagination defaulting to five connections per page.
- Configure connections using either an automated approach (IdP metadata XML upload) or a manual certificate and form-based setup.
- Enable encryption with selectable padding options (default ISO 10126) and generate, download, or regenerate encryption certificates.
- Enable user provisioning with unique identifier selection, position management, OU mapping, and standard user field mapping.
- Enable e-signature and Learning Reporter, each limited to one SSO connection at a time.
- Track all configuration changes through a date-filterable audit log with review-and-restore capability.
Details
Description
This release introduces a fully self-service dashboard in Cornerstone OnDemand that enables customer administrators to create, configure, and manage end-to-end inbound SAML Single Sign-On (SSO) connections. The experience is centered around a single landing page that provides a comprehensive grid view of all connections, both active and deleted, with details such as connection type, ID, status, the administrator who created it, the creation timestamp, and when the connection was last used by an end user.
From one place, administrators can manage connections, handle certificates, view or download metadata, and review mapping details. The dashboard supports both an automated configuration approach using an IdP metadata XML file and a manual approach using a certificate and form-based setup. It also supports advanced capabilities including user provisioning, encryption, e-signature, and Learning Reporter, all configurable through dedicated tabs on each connection. A built-in audit log tracks every change, recording before and after values and offering a review-and-restore action to roll back to a previous version.
Business Need
Until now, customers relied on Cornerstone support teams or external partners to configure new SSO connections or enable additional features on existing ones. Manual setup required technical understanding of SSO metadata files and often posed challenges for partners, significantly increasing lead time and introducing delays whenever a new feature was needed. The legacy experience limited dashboard access to internal teams, left administrators without direct control, and lacked a unified view of connections and their usage.
By moving this capability into a self-service dashboard, administrators can independently create, update, or delete SSO connections within minutes and enable advanced options such as encryption and provisioning without external dependencies. This results in faster setup, reduced friction, and a shorter support cycle, while giving administrators strong oversight, a standardized SSO posture, and instant visibility into connection status and usage for faster troubleshooting.
Key Features
- Administrators can create, update, delete, and restore inbound SAML SSO connections directly from a single self-service dashboard.
- A centralized landing page displays a grid view of all active and deleted connections, including type, ID, status, the creating administrator, the creation date and time, and the last-used timestamp.
- The grid supports filtering by status and creation date, with pagination set to display five connections per page by default.
- Connections can be configured using either an automated approach with an IdP metadata XML upload or a manual approach using a certificate and form-based configuration.
- Administrators can enable encryption with selectable padding options (defaulting to ISO 10126) and can generate, download, and regenerate the encryption certificate as needed.
- Administrators can enable user provisioning, configuring the unique identifier, position management, OU mapping, and standard user field mapping to create users on the fly.
- The dashboard supports e-signature and Learning Reporter, each of which can be enabled on only one SSO connection at a time.
- A date-filterable audit log tracks all configuration changes, recording before and after values and providing a review-and-restore action to revert to a previous version.
Deployment & Considerations
The dashboard is available in Stage at the start of the Unity release and in Production with the release, and is active by default. As of the July release, it supports inbound SAML and its associated features, with additional SSO types planned for future releases. The dashboard is accessed via Admin > Tools > Edge > Single Sign-On Administration.
Enabling the dashboard requires assigning eligible administrators to the dedicated role. Three new security permissions were created under the Core category; all are mapped to the role ID and carry no constraints. Note that e-signature is driven by portal-level configuration and is enabled separately, with the dashboard tab only providing visibility into which connection uses it. When changing the encryption padding option from the default, administrators should consult their IdP team to confirm compatibility.