Single Sign-On (SAML) - CTU & Permissions Details

Once SSO is set up, users can be created via your active directory, or in the usual way. Active directory users already have login details for your organisation, so they use the same credentials to log into MaxContact. SSO and non-SSO users can both log in without issue, side by side.

SSO is mainly configured by your internal IT team, but there are two front-end areas worth knowing: the CTU page and the Permissions page.


CTU page

Two SSO-related additions appear on the CTU page: a tick box to set a user to use SSO, and a Local Authentication button.

Single Sign-On tick box

A user created via SSO and your active directory appears in the CTU page with this tick box already assigned. Creating a user this way only sets up their basic login details. Other fields are left at their defaults.

CTU fieldAssigned by SSO?
First nameYes
Last nameYes
ActiveYes
LoginYes
Default roleYes
Single sign-onYes
PhotoNo
WebRTCNo
ExtensionNo
Auto login to campaignNo
Primary teamNo
Capacity planNo
TagsNo
Note. WebRTC and Primary team can be configured automatically during onboarding, even though SSO itself doesn't assign them.
Note. If you want an existing non-SSO user to log in via SSO going forward, ticking Single Sign-On on their account isn't enough on its own. You also need to update their Login field to match their SSO email address. If the login doesn't match, the system won't recognise them as the same user when they sign in via SSO, and creates a brand new duplicate account instead.

Local Authentication button

This button controls whether users can log in with a standard username and password alongside SSO.

While Local Authentication is enabled, both standard login and SSO work side by side. This is useful while you're still finishing your SSO setup, and lets you use the Password Creator (see below) to generate standard passwords for your users.

Selecting the Local Authentication button, then confirming, disables standard authentication for SSO users specifically. Non-SSO users are unaffected and can continue to log in as normal. This button is only available to users with the SSO Configuration Access permission.

Note. Once Local Authentication has been disabled this way, the same button's function changes: selecting it again switches SSO off entirely, for all users. Confirm this behaviour in your portal before relying on it, since it changes what the button does depending on its current state.

Password Creator

While Local Authentication is enabled, select the Local Authentication button to open a dialog where you can create a password to give to all users for standard login.

Since users may not already have a password set for standard authentication, use fill points to generate a password unique to each user rather than sending everyone the same one. Available fill points are the user's login, first name, last name, and the five custom data fields from their Custom Data tab.

For example, an admin sets a password of "password" followed by the Last name and a custom field holding each agent's postcode. Every user then receives a password reading "password.surname.postcode," unique to them despite following the same template.

Custom data and fill points

To use custom fields as fill points, a member of the admin team with access to the Permissions page needs to give the relevant roles permission to edit custom data fields. See Custom Data Fields for Email Signatures for how these fields work; the same custom data is used here.

Note. Changing a custom field's name applies across every user, but doesn't affect the values already entered in that field for each user.

Permissions page

SSO users have their roles assigned outside the portal, as part of the SSO process. Once a user is classed as an SSO user, their role can't be changed from within MaxContact.

A yellow padlock icon next to a user indicates their role was set as part of the SSO process. To change it, speak to whoever manages your active directory internally. A padlock icon next to a permission group or role indicates that group has been mapped via SSO.

Note. You can still edit permissions within existing roles, and create new roles, from within MaxContact. New roles still need to be mapped to users via your active directory before SSO users can be assigned them.

Related articles