SSO (Single Sign-On): Setup and Requirements
Setting up SSO (single sign-on) for Cribl.Cloud Government follows the same procedure as the commercial offering, with a few Government-specific differences. The full procedure is available in the Cribl.Cloud SSO documentation, where each Government difference is called out inline at the step where it applies.
Use the following links to jump to the relevant steps:
- No SSO bypass: Once SSO is configured, all users must authenticate through the configured SSO provider. Cribl.Cloud Government does not support bypassing SSO for local accounts or additional Organizations. See Bypass SSO with Multiple Organizations.
- SAML configuration: Cribl.Cloud Government uses placeholder ACS URL and Audience URI values until you save the connection, maps first and last names as
firstNameandlastName, and supports encrypted SAML assertions. See Configure SAML SSO. - Test Connection: The verification workflow is the same, but provides fewer diagnostic details in Cribl.Cloud Government due to regulatory restrictions. See Verify that SSO Is Working.
For the compliance context behind these requirements, including the FedRAMP boundary, FIPS 2FA, and PIV/CAC support, see Authentication: Identity, 2FA, and Access.