Kontakt.io offers a seamless and secure way for your organization's staff to access the Kio Cloud platform by leveraging Single sign-on (SSO) technology. This means that staff can log in to Kio Cloud using your organization's SSO identity provider (IdP), which is a more secure method compared to using a separate Kio Cloud username and password.
There are many benefits to implementing SSO with Kio Cloud, including:
Reduced administration time. You can manage staff access to the Kio Cloud platform from your organization's SSO identity provider. This is especially useful in larger organizations where the workforce regularly changes due to people joining, moving departments, leaving, or retiring.
Easier access. Your staff can seamlessly access Kio Cloud without needing to provide separate login credentials. They can log in using their SSO credentials, making the authentication process more convenient and efficient.
Security. With centralized user accounts managed from your SSO identity provider, you can apply security measures to all users, such as password strength, multi-factor authentication, and more.
About integrating your Kio Cloud with your SSO identity provider
Integrating Kio Cloud with your SSO identity provider streamlines the authentication process, enhances security, and provides a seamless user experience by leveraging a single set of login credentials across multiple applications.
The following provides a high-level overview of the integration.
Kio Cloud supported Single Sign-On (SSO) providers
Kontakt.io's Kio Cloud platform can integrate with one SSO identity provider of your choice that supports the Secure Assertion Markup Language (SAML) or OpenID Connect (OIDC) protocols. These are both widely adopted standards for enabling seamless and secure authentication across different applications and systems.
Secure Assertion Markup Language (SAML): Supported by many identity providers such as Microsoft Active Directory Federation Services (ADFS), Okta, OneLogin, and Ping Identity.
OpenID Connect (OIDC): Supported by many identity services including Google, Microsoft Azure Active Directory, Okta, Auth0, and Ping Identity.
OpenID Connect (OIDC)
Supported by many identity services including Google, Microsoft Azure Active Directory, Okta, Auth0, and Ping Identity.
Integration Setup
To enable the integration, trust needs to be established between Kio Cloud and your organization's SSO identity provider. This involves exchanging metadata and configuration information between the two systems. The metadata contains details about your SSO identity provider and the Kio Cloud platform as the Service Provider, allowing them to recognize and communicate with each other securely.
Your Kontakt.io Project Manager will guide your team through the entire integration process—from gathering the required metadata to setup, testing, and deployment.
Important integration highlights:
- Kontakt.io creates your organization's Kio Cloud account, which is identified by a unique Tenant ID and includes a dedicated account URL. For example: https://[tenantID].app.cloud.[us or uk].kontakt.io
- Authentication to your organization's Kio Cloud URL is only available for users from your verified domain.
- If you have multiple domains, your identity provider must be configured to support them.
- Your organization defines the default Kio Cloud apps, assigned roles, and campuses, for all first-time users.
User Authentication Flow
Once the integration setup is complete:
- Sign-in: Users sign in to your organization's Kio Cloud URL. They are presented with your organization's SSO identity provider sign-in page. The user enters their SSO credentials, and the SSO identity provider verifies them for authentication.
- Token exchange: Upon successful authentication, your SSO identity provider generates a token (such as a SAML or OIDC token). This token contains information about the user's identity, attributes, and authentication context. It is digitally signed by the SSO provider to ensure its integrity. Kio Cloud receives the SSO token from the user's browser and exchanges it with your SSO provider to obtain a token specific to the Kio Cloud platform.
- User creation and authorization: Upon successful validation of the token, Kio Cloud creates a user account for the authenticated user if one doesn't already exist.
User Permissions
Kio Cloud uses role-based access control (RBAC) to grant user permissions to each Kio App, and the Campuses they are granted access to. With SSO, both a user's roles and their campus access are managed through your identity provider and applied automatically each time they sign in.
- Only those assigned to the User Management Administrator role have permission to view and manage the roles assigned to users.
- This integration does not remove Kio Cloud users at any time. A user assigned to the User Management Administrator role can disable or delete users as needed.
Want to learn more?
Reach out to your Kontakt.io Sales Representative or submit a request to our support team and they will get you in touch with the right person.