Update your SAML SSO setup

Last updated:

This article explains how to update the metadata using a URL or XML file, or the certificate using a PEM file, for an existing SAML SSO configuration. If you're an organization admin, you can make these updates at any time. 

Before you begin

  • To update your organization's SAML setup, you must be an org admin. Subscription admins don't have permission to do this. See more about Organization users.
  • Have the new configuration details ready: the identity provider metadata URL, the metadata XML file, or the PEM certificate file.
  • Check whether SAML SSO is your subscription's only sign-in method. You can do this by going to Settings > Subscription settings and scrolling down to the Security and privacy section. You can check to see if SAML SSO is the only method listed under Sign-in methods.If it is, there is no email and password fallback, so the active session you start in the next section is your only way back into the setup.

Start a new session

Before you make changes, log out of Pendo and log back in to start a new, active session. If your SAML changes accidentally break sign-in, you'll still be able to use this active session to get back into the setup and fix it.

Update your SAML settings

You can update your SAML setup from your organization settings. If you don't see this option in your menu, you may not have org admin permissions. To learn more about this, see Organization users.
  1. From the top-right menu, go to Settings > Organization settings
  2. Select the SSO tab.
  3. From the left-side options, select SAML.
  4. Choose the SAML configuration you want to update. You can do this by selecting the name in the list or by hovering over the row and selecting the Edit icon.
  5. Choose how you'd like to update the metadata or replace the certificate. You have three options.

    Type Details
    URL
     
    Use this if you have a URL for your identity provider metadata. When you select this option, a text field opens where you can enter the URL.
    Metadata (XML) Use this if you have an XML file with your metadata. When you select this option, an option to upload a file with an .xml extension appears.
    Certificate (PEM) Use this if you have a PEM file for your certificate. When you select this option, an option to upload a file with a .pem extension appears.
  6. Once you're done, select Save configuration to apply the new SAML settings immediately.
  7. Keep this page open. You may need it if you experience issues with the SSO when verifying your changes to fix anything that isn't working.

Note: Check with your identity provider that the new certificate information is active and the metadata you uploaded matches exactly. Once you've saved your edits, you can't revert to your previous setup.

Verify your changes

Verify your changes right away. This is what prevents users from getting locked out.
  1. Open an Incognito window, Private mode, or a different browser than you normally use, so you aren't logged in.
  2. Sign in to Pendo using the SSO option on the login screen.

If the certificate updates are correct, you'll be logged in through SSO with no errors.

Troubleshooting sign-in issues

If you get an error when verifying your changes, go back to the browser you were working in (from step 7) and check that you entered the metadata or certificate correctly. Do this right away, before your active session expires, so you don't get locked out before you can fix it.
If correcting the configuration doesn't restore sign-in, contact Pendo Support.

Important: if SAML SSO is the only sign-in method for the subscription, users will not be able to use an email and password to log in. They will be locked out until the issue has been fixed.

Was this article helpful?
0 out of 0 found this helpful