DOMO - SSO configuration

DOMO - SSO configuration

Idea
This documentation has been tested and approved by Kelvin Zero's team
Quote
This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Domo using MPAS. SSO simplifies user authentication by allowing access to multiple applications with a single set of credentials. This integration enhances security and improves user experience across your organization.
Warning
To set up Multi-Pass with Domo, ensure you meet the following requirements:
- Domo admin rights
- MPAS Admin rights
- Make sure that all users intended to use SSO in Domo are registered in your IdP and have the necessary permissions to access Domo.
Important: Custom elements in URLs (like realm names) are case sensitive. Make sure to match the exact casing from your environment.




DOMO - SSO configuration





Step 1 - Configure Multi-Pass as the Identity Provider (IdP)


  1. Select the correct tenant and go to Integrations, click on Applications
  2. Select in the custom integration section SAML
  3. Complete the SAML setup with the information below :
FieldValue
Client ID (=SP Entity ID)https://<DOMO_SUBDOMAIN>.domo.com
Namedomo
DescriptionDomo SSO integration
Assertion Consumer Service URLhttps://<DOMO_SUBDOMAIN>.domo.com/auth/saml
NameID Policy Formatemail
  1. Select Download Tenant Certificate and save the file locally

  1. Click add integration
  2. Click Advanced Console

  1. Click Clients and search for Domo
  2. Make sure that the following fields are well completed : 
General settings (Multi-Pass)
FieldValue
Client IDhttps://<DOMO_SUBDOMAIN>.domo.com
NameDomo
DescriptionDomo SSO integration
Always display in UION

Access settings (Multi-Pass)
FieldValue
Home URL (IdP-initiated)https://ca.auth.kzero.com/realms/<TENANT_NAME>
Valid Redirect URIs (ACS)https://<DOMO_SUBDOMAIN>.domo.com/auth/saml
IDP-Initiated SSO URL Name<APP_NAME>

SAML Capabilities
SettingValue
Name ID Formatemail
Force Name ID FormatON
Force POST BindingON
Include AuthnStatementON

Signature & Encryption
SettingValue
Sign DocumentsON
Sign AssertionsON
  1. Now that you have checked the different parameters, change to the tab called “Keys”.
    1. Make sure that both parameters are switched to OFF.
  2. Now go to the “Advanced” tab.
    1. The field “Assertion Consumer Service POST Binding URL” must equal the Valid Redirect URIs (ACS).

Step 2 - Configure Domo as the Service Provider (SP)

  1. Log into Domo as an Administrator
  2. Click the wrench on the left side menu and select Single Sign On (SSO) under Authentication
  3. Under Configuration select Configure beside SAML
  4. Select Manual Entry
  5. Fill in the IdP Endpoint URL and Entity ID based on the table below :
SettingValue
Identity Provider Endpoint URLhttps://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml
Entity IDhttps://ca.auth.kzero.com/realms/<TENANT_NAME>
  1. Upload the Multi-Pass Certificate
  2. Select Allowed (all domains) under Just-in-time user provisioning
  3. Select SSO (Domo auth screen) under User login experience
  4. Check the box beside Sign authentication requests
  5. Click Save and Enable

Step 3 - Testing Multi-Pass to Domo

  1. Navigate to your Domo login page
  2. Click Sign in and you will be redirected to Multi-Pass for authentication
  3. Complete the authentication and access Domo
    • Related Articles

    • Mulesoft - SSO Integration

      This application has been formally tested by Kelvin Zero Inc. This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Mulesoft using Multi-Pass. SSO simplifies user authentication by allowing access to multiple ...
    • SAML SSO Integration Guide

      This guide provides an overview of how to configure SAML Single Sign-On (SSO) between Multi-Pass and a third-party Service Provider (SP). Multi-Pass acts as the Identity Provider (IdP) in this federation model. Multi-Pass is working on SCIM support ...
    • Zoho One - SSO configuration

      This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Zoho One using MPAS. SSO simplifies user authentication by allowing access to multiple ...
    • D2L Brightspace - SSO Integration

      This application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk. This documentation provides a step-by-step guide to ...
    • Vanta - SSO configuration

      This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Vanta using MPAS. SSO simplifies user authentication by allowing access to multiple ...