> ## Documentation Index
> Fetch the complete documentation index at: https://docs.levelblue.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configuring Single Sign-On

|                       |           |              |         |             |
| --------------------- | --------- | ------------ | ------- | ----------- |
| **Role Availability** | Read-Only | Investigator | Analyst | **Manager** |

To use a Single Sign-On (SSO) vendor to log in to a USM Anywhere instance, you need to create a new SSO configuration.

<Note>
  Only users with the manager role will be able to create, edit, and delete SSO configurations.
</Note>

**To configure SSO in USM Anywhere**

1. Go to **Settings** > **Single Sign On**.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/9CUoTpOEpmQqx8O4/images/usm-anywhere/sso.config1.png?fit=max&auto=format&n=9CUoTpOEpmQqx8O4&q=85&s=071dc8d13a43b652fa567d8aa5e711b1" alt="" width="1919" height="934" data-path="images/usm-anywhere/sso.config1.png" />
</Frame>

2. Click **New SSO**. The Add New SSO Configuration dialog box opens.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/9CUoTpOEpmQqx8O4/images/usm-anywhere/sso.config2.png?fit=max&auto=format&n=9CUoTpOEpmQqx8O4&q=85&s=1879a5d0d887feadc80a2c1f52e06ca1" alt="" width="1917" height="934" data-path="images/usm-anywhere/sso.config2.png" />
</Frame>

3. Enter the SSO configuration provided by your SSO vendor:
   * **SSO Name:** You can enter the name you want; this name will be shown on the Login page.
   * **Identity ID:** The vendor provides you with this information
   * **Single Sign-On URL Endpoint:** The vendor provides you with this information
   * **Public Key:** The vendor provides you with this information
4. Click **Save**.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/9CUoTpOEpmQqx8O4/images/usm-anywhere/sso.config3.png?fit=max&auto=format&n=9CUoTpOEpmQqx8O4&q=85&s=db397f9e7287ab6fb3f19c4118d8b6d4" alt="" width="1921" height="934" data-path="images/usm-anywhere/sso.config3.png" />
</Frame>

5. In the SSO Confirmation dialog box, click the checkbox to confirm your changes, and then click **Confirm**.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/9CUoTpOEpmQqx8O4/images/usm-anywhere/sso.config4.png?fit=max&auto=format&n=9CUoTpOEpmQqx8O4&q=85&s=588b778168a1360d3a539b0f0a399bdd" alt="" width="1921" height="933" data-path="images/usm-anywhere/sso.config4.png" />
</Frame>

After successfully creating the new configuration, the system will be restarted to apply your changes. After the system restart, go to the Login page and see your new SSO configuration.

6. Go back to the SSO page, and then click the **View** button for your newly created SSO integration.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/9CUoTpOEpmQqx8O4/images/usm-anywhere/sso.config5.png?fit=max&auto=format&n=9CUoTpOEpmQqx8O4&q=85&s=85dc3cb066c8d25536ef498939abab4a" alt="" width="1918" height="934" data-path="images/usm-anywhere/sso.config5.png" />
</Frame>

Use the information provided on the screen to configure the SAML settings in your SSO provider’s portal. The primary field to complete is the **Single Sign-On URL**; other fields may be optional depending on your provider’s requirements.

7. **(Optional)** If you want to encrypt the assertions, use the certificate by clicking **Show more**.
8. **(Optional)** Go to the Single Sign On page and click the **Edit** button. The Edit SSO Configuration dialog box opens.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/ADqAu3z60kScsszN/images/usm-anywhere/sso.config6.png?fit=max&auto=format&n=ADqAu3z60kScsszN&q=85&s=c25236a07547775bfdbff851b4a57175" alt="" width="1918" height="934" data-path="images/usm-anywhere/sso.config6.png" />
</Frame>

9. **(Optional)** If you need it, enable SAML Mapping. The mapping will depend on the information that is sent in your SSO vendor assertions.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/ADqAu3z60kScsszN/images/usm-anywhere/sso.config7.png?fit=max&auto=format&n=ADqAu3z60kScsszN&q=85&s=6055a6c65d4ffba823688579612449e3" alt="" style={{ width:"57%" }} width="872" height="754" data-path="images/usm-anywhere/sso.config7.png" />
</Frame>

* You will have to add the value you use in your vendor if it does not correspond to the following:
  * **Email:** email
  * **Name:** fullName
  * **Role:** roles
* Add role name mapping if you use roles other than USM Anywhere roles (You can add more than one role for a type, each entry has to be added by pressing enter). Roles Type from USM Anywhere:
  * Manager
  * Analyst
  * Read Only
  * Investigator
* If a user does not have a role assigned that maps to USM Anywhere’s roles, the user will be assigned the *Read Only* role.

10. **(Optional)** Enable the **SSO Required** option. Go to **Settings** > **System** > **SSO settings**. If this option is enabled, it forces all users to use the SSO to login. (Manager users can always login using their user/password) (Available from version 7.76).
