Steps to configure SAML SSO for BambooHR
About BambooHR
BambooHR is a comprehensive HR software platform designed to streamline employee management, payroll processing, and benefits administration, making it easier for businesses to manage their HR efficiently.
The following steps will help you enable single sign-on (SSO) for BambooHR from Identity360.
Prerequisites
- The MFA and SSO license for Identity360 is required to enable SSO for enterprise applications.
- Log in to Identity360 as an Admin or Super Admin.
- Navigate to Applications > Application Integration > Create New Application, and select BambooHR from the applications displayed.
Note: You can also find BambooHR from the search bar located at the top.
- Under the General Settings tab, enter the Application Name and Description.
- Under the Choose Capabilities tab, choose SSO and click Continue.
General Settings of SSO configuration for BambooHR.
- Under Integration Settings, navigate to the Single Sign On tab and click Metadata Details. Copy the Login URL and Signing Certificate values, which will be used later during the configuration of BambooHR.
Integration Settings of SSO configuration for BambooHR.
BambooHR (service provider) configuration steps
- Log in to BambooHR with admin privileges.
- Click the Settings icon at the top-right corner.
Portal view of BambooHR.
- On the Settings page, click Apps.
BambooHR settings.
- Navigate to SAML Single Sign-On and click Install.
SAML SSO installation in BambooHR.
- Paste the Login URL copied from step 6 of the prerequisites and paste in the SSO Login URL field.
- Paste the Signing Certificate copied from step 6 of the prerequisites in the x.509 Certificate field.
- Check Allow optional email & password login if required.
- Click Install.
SAML SSO configuration in BambooHR.
- Go to the Account tab and copy the company URL, which will be used later during Identity360 configuration.
Service provider identifier in BambooHR.
Identity360 (identity provider) configuration steps
- Switch to Identity360's application configuration page.
- In the SP identifier field, enter the company name from the URL copied from step 9 of BambooHR configuration. For example, if the company URL is xyz.bamboohr.com, then xyz is your SP identifier.
- Enter the Relay State parameter, if necessary.
Note: Relay State is an optional parameter used with a SAML message to remember where you were or to direct you to a specific page after logging in.
- Click Save.
Integration Settings of SSO configuration for BambooHR.
- To learn how to assign users or groups to one or more applications, refer to this page.
Your users will now be able to sign in to BambooHR through the Identity360 portal.
Note: For BambooHR, both SP-initiated and IdP-initiated flows are supported.
Steps to enable MFA for BambooHR
Setting up MFA for BambooHR using Identity360 involves the following steps:
- Set up one or more authenticators for identity verification when users attempt to log in to BambooHR. Identity360 supports various authenticators, including Google Authenticator, Zoho OneAuth, and email-based verification codes. Click here for steps to set up the different authenticators.
- Integrate BambooHR with Identity360 by configuring SSO using the steps listed here.
- Now, activate MFA for BambooHR by following the steps mentioned here.
How does MFA for applications work in Identity360?