This article explains how to update the metadata using a URL or XML file, or the certificate using a PEM file, for an existing SAML SSO configuration. If you're an organization admin, you can make these updates at any time.
Before you begin
- To update your organization's SAML setup, you must be an org admin. Subscription admins don't have permission to do this. See more about Organization users.
- Have the new configuration details ready: the identity provider metadata URL, the metadata XML file, or the PEM certificate file.
- Check whether SAML SSO is your subscription's only sign-in method. You can do this by going to Settings > Subscription settings and scrolling down to the Security and privacy section. You can check to see if SAML SSO is the only method listed under Sign-in methods.If it is, there is no email and password fallback, so the active session you start in the next section is your only way back into the setup.
Start a new session
Update your SAML settings
- From the top-right menu, go to Settings > Organization settings
- Select the SSO tab.
- From the left-side options, select SAML.
- Choose the SAML configuration you want to update. You can do this by selecting the name in the list or by hovering over the row and selecting the Edit icon.
-
Choose how you'd like to update the metadata or replace the certificate. You have three options.
Type Details URL
Use this if you have a URL for your identity provider metadata. When you select this option, a text field opens where you can enter the URL. Metadata (XML) Use this if you have an XML file with your metadata. When you select this option, an option to upload a file with an . xmlextension appears.Certificate (PEM) Use this if you have a PEM file for your certificate. When you select this option, an option to upload a file with a .pemextension appears. - Once you're done, select Save configuration to apply the new SAML settings immediately.
- Keep this page open. You may need it if you experience issues with the SSO when verifying your changes to fix anything that isn't working.
Note: Check with your identity provider that the new certificate information is active and the metadata you uploaded matches exactly. Once you've saved your edits, you can't revert to your previous setup.
Verify your changes
- Open an Incognito window, Private mode, or a different browser than you normally use, so you aren't logged in.
- Sign in to Pendo using the SSO option on the login screen.
If the certificate updates are correct, you'll be logged in through SSO with no errors.
Troubleshooting sign-in issues
Important: if SAML SSO is the only sign-in method for the subscription, users will not be able to use an email and password to log in. They will be locked out until the issue has been fixed.