Enable single sign-on authentication

By default, end users authenticate on the mobile app by entering a username and password on the login screen. Administrators can also enable Single Sign-On (SSO). When SSO authentication is enabled, when a user is already authenticated and signed in using their organization's identity provider (IDP), they do not need to sign in again to access the ​​​​​​BlackBerry AtHoc​​​​ mobile app. If a user is not signed in, they are redirected to their organization's customer IDP login when they attempt to sign in. This IDP is managed by the organization or by a third party vendor that provides IDP services. The IDP authenticates the user. The user is then redirected to the ​​​​​​BlackBerry AtHoc​​​​ mobile app. If the user is already signed in to the IDP, they are automatically redirected to the BlackBerry AtHoc​​​​ mobile app with an active session. ​​​​​​When SSO authentication is enabled, it becomes the primary authentication method.​​​​​​

When SSO authentication is enabled, biometric authentication is disabled and the Face ID for alert publishing and reporting setting is not displayed on the Organization settings screen.​​​​

  1. ​​​​​​In the navigation bar, click ​​​​​​​​​​The Settings icon.​​​​
  2. ​​​​​​On the ​​​​​​Settings​​​​ screen, in the ​​​​​​Users​​​​ section, click ​​​​​​User Authentication​​​​.​​​​
  3. ​​​​​​​​​​​​On the​​​​​​ User Authentication​​​​ screen, in the ​​​​​​Assign Authentication Methods to Applications​​​​ section, in the​​​​​​ Mobile App​​​​ section, select​​​​​​ Single Sign-On ​​​​from the​​​​​​ Authentication Method ​​​list. The​​​​​​ Sign In URL ​​​​section appears and is automtically populated with a URL in the following format: <​​​​​​server​​​​>/selfService/Account/MobileSSO. This URL is used when users attempt to access the mobile app using SSO authentication.​​​​​​​​
  4. ​​​​​​Optionally, select ​​​​​​Username and Password​​​​ from the ​​​​​​Alternative Authentication Method​​​​ list to enable both single sign-on and Username/Password user authentication.​​​​
  5. ​​​​​​Click ​​​​​​Configuration​​​​.​​​​
    ​​​​​​If the ​​​​​​Configuration​​​​ button is not available, SSO is not enabled. For more information, see ​​​​​​Enable single sign-on as an authentication method​​​​ in the ​​​​​​​​​​​​​​​​​​​​​​ BlackBerry AtHocSingle Sign-On​​​​​​​​ guide.​​​​
  6. On the ​​​​​​Mobile SSO configuration​​​​ window,export SP and IDP settingsandthenimport IDP settings or configure these settings manually. For details, see "​​​​​​Configure identity provider settings​​​​" and "​​​​​​Configure service provider settings" ​​​​in the​​​​​​​​​​​​​​​​​​ ​​​​ BlackBerry AtHoc Single Sign-On ​​​​​​​​guide.
  7. ​​​​​​Click ​​​​​​Apply​​​​.​​​​
  8. ​​​​​​Click ​​​​​​Save​​​​.​​​​