USM Content
Learn how to set up SAML-based SSO for your Smartsheet Enterprise plan.
Configure SAML for domain-level single sign-on to Smartsheet
USM Content
What's domain-level SAML?
Domain-level SAML lets you implement a unified single sign-on (SSO) experience for all Smartsheet users within a verified and activated domain, regardless of their plan type or department.
Any existing plan-level SAML configurations remain functional for users in that domain. Once you activate domain-level SAML, it overrides plan-level SAML for users in that domain. For a full explanation of how domain-level and plan-level policies interact, see What determines which sign-in options users see?
The user movement policy supports only plan-level SAML configurations and is incompatible with domain-level SAML. You can't switch to domain-level SAML if you've already configured a user movement policy.
Before you begin
- This feature is available only on Enterprise plans. You need a System Admin and an IT Administrator to configure domain-level SAML.
- Verify and activate your domains through the Domain Management screen before setting up a domain-level SAML configuration. Learn how to activate a domain.
Activate the Smartsheet V2 application in Okta.
This requirement applies only to the Okta-based SAML configuration.
- Set up SAML in your IdP and update the SAML attributes in Smartsheet during the SAML configuration. Find the required attributes in Smartsheet for the SAML exchange process.
Domain activation and configuration access
The Enterprise plan that validated and activated the domain is the only one that can configure and apply domain-level SAML settings for all users within that domain.
If other Enterprise plans have validated the same domain, they can configure a draft domain-level SAML configuration, but they can't apply those settings because they didn't activate the domain.
About plan-level SAML configurations
- If you don't have an existing plan-level SAML setup or are new to Smartsheet, you can only configure SAML at the domain level. If you still need plan-level SAML, contact your Customer Success Manager (CSM).
- Existing plan-level or new domain-level configurations remain functional for users in that domain until the Smartsheet SAML certificate expires. Learn more about certificate expiry.
- If you have an existing plan-level SAML setup, Admin Center displays a warning showing the number of days remaining before your current plan-level configurations expire.
Set up SAML for single sign-on to Smartsheet
- Go to the Admin Center and select the Menu icon.
- Navigate to the Settings tab and select Authentication.
- Select Add a SAML IdP.
- Select Configure on either of the following:
Okta-based SAML configuration
Before starting the Okta wizard, make sure you have the following open and ready:
- The Okta Admin Console with the Smartsheet V2 app selected
- The Smartsheet Admin Center (where you complete the steps below)
You can switch between the Okta Admin Console and Smartsheet Admin Center during configuration.
- Enter a name for your Okta SAML configuration in the Name Okta IdP field.
Copy the values from the Assertion Consumer Service (ACS) URL and Audience Restriction (Entity ID) fields, and paste them into the ACS URL and Audience URI fields in the Smartsheet v2 Okta app. This establishes Smartsheet as a service provider and allows you to get SAML metadata from your Okta instance.
Brandfolder Image
- Follow the instructions on the screen to get the Okta metadata URL and then select Save & Next.
- You now need to test your connection by signing in to Smartsheet using Okta. Select Verify connection.
- After verifying your connection, select the I have successfully verified the connection checkbox.
Select Save & Next.
Brandfolder Image
- Assign your active domains to Okta using the drop-down field or select Add domain to find any domains you wish to add.
Select Save & Next.
Brandfolder Image
- Follow the instructions on the screen to create an Okta bookmark app, which allows your users to sign into Smartsheet from their Okta app home.
- Select the checkbox to confirm you've successfully created an Okta bookmark app for Smartsheet.
Select Finish.
Brandfolder Image
Custom SAML configuration
Follow the instructions on the screen to establish Smartsheet as a relying party and then select Next.
Brandfolder Image
- Enter a name for your custom SAML configuration in the Name SAML IdP field.
Import your SAML IdP metadata from either an XML file or a public URL that hosts an XML file from your identity provider.
The XML URL option is the recommended method for importing your metadata.
Select Save & Next.
Brandfolder Image
- You now need to test your connection by signing in to Smartsheet using your custom SAML IdP. Select Verify connection.
- After verifying your connection, select the I have successfully verified the connection checkbox.
Select Save & Next.
Brandfolder Image
- Assign your active domains to your custom SAML IdP using the drop-down field or select Add domain to find any domains you wish to add.
Select Finish.
Brandfolder Image
You can't enable your new SAML configuration without first verifying your SAML IdP connection.
Direct people to sign in at a friendly CNAME URL
Smartsheet provides a default SSO URL for your organization. You can create a CNAME to give users a more company-specific sign-in URL instead; for example, smartsheet.yourcompany.com instead of the standard Smartsheet SSO URL.
Once you've completed your SAML setup, go to your DNS provider and create a CNAME record pointing your custom URL to the Smartsheet SSO service at sso.smartsheet.com.
Maintain your domain-level SAML configuration
After your domain-level SAML configuration is active, keep an eye on your IdP certificate expiration dates. An expired certificate disrupts SSO for every user in the domain.
When it's time to rotate or replace a certificate, follow the steps in Replace an expired IdP certificate.
What should I do if I experience issues during the transition to domain-level SAML?
Contact Smartsheet Support for assistance.
How can I revert back to plan-level SSO settings if needed?
After transitioning to domain-level SAML configuration, you can't revert to plan-level SSO settings. Ensure you’re prepared for this change before implementation.
Are there any additional costs involved in moving to domain-level SAML configuration?
No. There aren’t additional costs for enabling domain-level SAML configuration; it's included in your existing Smartsheet Enterprise plan.
Can I have different SAML configurations for different domains?
Yes. You can configure different SAML settings for each validated and activated domain. This flexibility allows for tailored security settings across various segments of your plan.
How does this change affect my current users' sign-in experience?
Once domain-level SAML is configured for a validated and activated domain by a System Admin on an Enterprise plan, all users in that domain, regardless of their plan type, must use the prescribed SAML sign-in method. However, all other plan-level configurations (such as Google SSO, Entra ID SSO, email and password, etc.) are still available to end users on that plan.
What happens to existing user sessions when the domain-level SAML configuration is activated?
Existing sessions should remain unaffected. However, once a user signs out, they need to sign back in using the new domain-level SAML configuration.