Steps to configure SAML SSO for enableHR
About enableHR
enableHR is a cloud-based human resources (HR) and work health and safety management platform. Its main aim is to help businesses streamline people processes, enforce compliance with employment and safety laws, and reduce the HR team's administrative burden.
The following steps will help you enable SSO for enableHR software from Identity360.
Prerequisites
- The MFA and SSO license for Identity360 is required to enable SSO for enterprise applications.
- Log in to Identity360 as an Admin, Super Admin, or Technician with a role that has Application Integration and Single Sign-on permissions.
- Navigate to Applications > Application Integration > Create New Application and select enableHR from the applications displayed.
Note: You can also find enableHR using the search bar located at the top.
- On the General Settings tab, enter the Application Name and Description.
- Under Choose Capabilities, select Single Sign-on and click Continue.
General Settings of SSO configuration for enableHR.
- On the Integration Settings tab, navigate to Single Sign On and click IdP Details. Copy the Login URL, Logout URL, and Metadata values, which will be used later during the configuration in enableHR.
Integration Settings of SSO configuration for enableHR.
enableHR (service provider) configuration steps
- Log in to enableHR, the service provider (SP), as an administrator.
- Click Settings > Account Settings.
- Click Security > SSO.
- Leave the Identity Provider (IdP) field blank.
- Check the Enable SAML Identity Provider box.
- In the SAML Identity Provider field, paste the Metadata value copied in step 6 of the prerequisites.
- Select the appropriate Authentication Mode. If you intend to manage users and their roles within enableHR, set it to AuthenticationOnly mode. If you intend to use Access (Authorization) mode, please contact enableHR.
- Set New User Access to ESS – eSS Employee as that is the safest option recommended by enableHR.
- In the Login URL field, paste the Login URL value copied in step 6 of the prerequisites.
- In the Logout URL field, paste the Logout URL value copied in step 6 of the prerequisites.
- Click Update.
Identity360 (identity provider) configuration steps
- Switch to the application configuration page of Identity360, the identity provider (IdP).
- Enter the Relay State parameter, if necessary.
Note: The Relay State is an optional parameter used with a SAML message to remember where you were or to direct you to a specific page after logging in.
- Click Save.
Integration Settings of SSO configuration for enableHR.
- To learn how to assign users or groups to one or more applications, refer to this page.
Your users will now be able to sign in to enableHR through the Identity360 portal.
Note: For enableHR, both IdP- and SP-initiated flows are supported.
Steps to enable MFA for enableHR
Setting up MFA for enableHR using Identity360 involves the following steps:
- Set up one or more authenticators for identity verification when users attempt to log in to enableHR. Identity360 supports various authenticators, including Google Authenticator, Zoho OneAuth, and email-based verification codes. Click here for steps to set up the different authenticators.
- Integrate enableHR with Identity360 by configuring SSO using the steps listed here.
- Now, activate MFA for enableHR by following the steps mentioned here.
How does MFA for applications work in Identity360?