Configuration · guide

Setting up SSO for a Webex organization

Webex Control Hub

Verified 2026-09-30 · 69 sources · tier 2

For Webex organization administrator configuring SAML single sign-on.

Webex Control Hub enables administrators to configure SAML 2.0 single sign-on using single or multiple identity providers 52 36. Webex lets an organization set up SSO with multiple IdPs and uses routing rules to decide which IdP to send each user to 36.

Before you start

For SSO with Control Hub, your identity provider must conform to the SAML 2.0 specification 52. Setting up multiple identity providers requires the Full Admin role in Control Hub, and routing-rule behaviour should be planned beforehand 35. If your organization uses Directory Connector, all users must be provisioned with Directory Connector when using multiple IdPs 13. If you have Webex Meetings sites that are not managed in Control Hub, a separate SSO integration is required for them 33.

What changes by situation

Pick your answers to see only your path. Nothing is sent anywhere until you make a plan.

Which SAML identity provider will authenticate your users?
One IdP for the whole organization, or several with routing rules?
Which certificate should sign the Webex service-provider metadata?

Three questions. One permanent page you can send to your manager.

Step 1 Verify and claim user email domains

Do

In Control Hub, go to Management > Organization Settings > Domains 16. Add a Webex verification token to each user email domain's DNS TXT record and click Verify 16. Claim the verified domain so new users who sign up with that domain join your organization 15. Ensure all domains planned for Just-In-Time (JIT) provisioning are verified, claimed, and turned on 31.

Verify

Each domain shows as verified and claimed in the Control Hub domain list 16 15.

Rollback

Suggested rollback: Remove unverified domain records from the domain settings in the management portal.

Step 2 Start the SSO wizard, select SP certificate, and download metadata

Self-signed by Cisco

Do

In Control Hub, navigate to Management > Security > Authentication, select the Identity provider tab, click Activate SSO, and select SAML 1. Choose Self-signed by Cisco, which is Cisco's recommendation and requires renewal once every 5 years 7. Download the Webex service provider metadata file, named idb-meta--SP.xml 58.

Verify

Verify that the downloaded file is saved locally with the naming pattern idb-meta--SP.xml 58.

Rollback

Suggested rollback: Cancel or exit the configuration wizard without saving changes.

Signed by a public certificate authority

Do

In Control Hub, navigate to Management > Security > Authentication, select the Identity provider tab, click Activate SSO, and select SAML 1. Choose Signed by a public certificate authority, noting that this requires more frequent metadata updates unless the IdP vendor supports trust anchors 6. We infer that an organization choosing a public-CA-signed SP certificate should expect to repeat the SP metadata upload to its IdP more often than one using the Cisco self-signed certificate 48. Download the Webex service provider metadata file, named idb-meta--SP.xml 58.

Verify

Verify that the downloaded file is saved locally with the naming pattern idb-meta--SP.xml 58.

Rollback

Suggested rollback: Cancel or exit the configuration wizard without saving changes.

Step 3 Create the Webex application in the IdP

Microsoft Entra ID

Do

In Microsoft Entra ID, open the Webex application added or created from the application gallery and configure SAML single sign-on with the Control Hub metadata file 22. In Basic SAML Configuration, copy the Reply URL value into the Sign on URL field and save 25. Note that Microsoft Learn's Cisco Webex Meetings Entra tutorial configures SSO in Webex Site Administration under Common Site Settings > SSO Configuration rather than in Control Hub 34. Be aware that existing Webex customers with previous federation configurations may hit issues with the standard Entra ID Webex template because of SAML attribute changes 23.

Verify

In the Entra Basic SAML Configuration, verify that the Identifier and Reply URL are populated from the metadata and that the Sign on URL matches the Reply URL 25.

Rollback

Suggested rollback: Delete or disable the newly created enterprise application in your identity platform.

Okta

Do

In the Okta admin portal, add the Cisco Webex application from Applications > Add Application and select SAML 2.0 40. Configure the application settings so the application icon is not displayed to users or in the Okta Mobile App 44, adhering to the requirement that Control Hub SSO supports only service-provider-initiated flows 57. Copy the entityID and the AssertionConsumerService location from the Webex metadata file into the Okta app's advanced SAML settings 46.

Verify

Verify that the entityID and AssertionConsumerService location in the Okta application match the downloaded Webex metadata file 46.

Rollback

Suggested rollback: Delete or deactivate the application integration in your identity provider portal.

Another SAML 2.0 IdP

Do

In your SAML 2.0 identity provider, create a new service provider application using the imported idb-meta--SP.xml metadata file 52 58. Ensure the application is configured for service-provider-initiated flows only 57. Cisco recommends including Single Logout in the metadata configuration so user tokens are invalidated at both the IdP and the SP, preventing sessions from remaining valid after a user signs out of Webex 56 39.

Verify

Suggested check: Confirm in the identity provider application settings that the entity ID, Assertion Consumer Service URL, and single logout endpoints match the imported metadata.

Rollback

Suggested rollback: Remove or unpublish the relying party trust or service provider configuration in the identity provider.

Step 4 Configure user assignments and assertion attributes

Microsoft Entra ID

Do

Assign users or groups to the Entra Webex app 17. Ensure the IdP sends a uid attribute mapped to the user's email address or User-Principal-Name 65. Webex supports mapping up to 5 email addresses to the uid, and the IdP must match 1 user email address to the uid at sign-in 66. The Cisco Entra ID article lists 3 supported NameID formats: SAML 2.0 transient and SAML 1.1 unspecified and SAML 1.1 emailAddress 21.

Verify

Verify assigned users and groups in the Entra ID application assignment list 17. Cisco recommends using a SAML tracer to verify the NameID format and ensure the assertion has a uid attribute matching a Webex user 26 67.

Rollback

Suggested rollback: Remove assigned users or groups from the enterprise application.

Okta

Do

In the Okta admin portal, assign the users and groups who need access to Webex, as Cisco notes the integration will not work without this assignment 41. Ensure the IdP sends a uid attribute mapped to the user's email address or User-Principal-Name 65. Note that Webex supports 3 NameID formats and uses the first NameID entry listed in the IdP metadata 43.

Verify

Verify that the intended user accounts and groups appear on the Assignments tab of the Okta Webex application 41.

Rollback

Suggested rollback: Unassign users and groups from the application integration.

Another SAML 2.0 IdP

Do

Configure the SAML assertion to send a uid attribute mapped to the user's email address or User-Principal-Name 65. Ensure the IdP matches 1 user email address to the uid at sign-in 66. If your identity provider uses an alternative attribute name for username or primary email, you can rename uid in the Webex SAML wizard to match, such as email or upn 53.

Verify

Suggested check: Use a browser extension to inspect a generated SAML response and ensure the uid or renamed attribute contains the expected email or principal name.

Rollback

Suggested rollback: Revert attribute statement definitions in the identity provider.

Step 5 Export IdP metadata and import into Control Hub

Microsoft Entra ID

Do

In Entra ID, download the Federation Metadata XML from the SAML Signing Certificate section 17. Return to the Control Hub SAML wizard and import the file 17. Choose More secure if the metadata is signed by a public CA, or Less secure if it is self-signed 30.

Verify

Verify that Control Hub successfully loads the metadata and displays the IdP entity ID, signing certificate, NameID format, and SSO service URL 29.

Rollback

Suggested rollback: Cancel out of the metadata import step in the wizard.

Okta

Do

In the Control Hub SAML wizard, import the Okta metadata and select Less secure, because Okta does not sign its metadata 45.

Verify

Verify that Control Hub imports the metadata containing the IdP entity ID, signing certificate, NameID format, and SSO service URL 29.

Rollback

Suggested rollback: Cancel out of the metadata import step in the wizard.

Another SAML 2.0 IdP

Do

In the Control Hub wizard, import the metadata file and choose More secure if the metadata is signed by a public CA, or Less secure if it is self-signed 30.

Verify

Verify that the imported metadata populates the IdP entity ID, signing certificate, NameID format, and SSO service URL 29.

Rollback

Suggested rollback: Cancel out of the metadata import step in the wizard.

Step 6 Configure SAML attribute mapping and JIT provisioning

Do

In the Control Hub wizard, rename the uid attribute if you agreed on an alternate name with your IdP owner, such as email or upn 53. If desired, configure JIT settings to create or activate a user when no active user is found, and to update existing user attributes from mapped SAML attributes 32. Note that JIT requires that the user email domains are verified, claimed, and turned on 31.

Verify

Confirm that the attribute mapping displayed in the wizard reflects the chosen attribute name 53.

Rollback

Suggested rollback: Clear custom attribute mappings back to default settings and leave JIT toggles off.

Step 7 Test SSO from Control Hub

Do

In the Control Hub wizard, click Test SSO setup 62. Copy the test URL into a private browser window to avoid interference from cached sign-in data 62 68. Do not test the SSO integration from the identity provider interface 14.

Verify

Authenticate using test user credentials in the private browser window and confirm successful sign-in 62. If authentication fails, use a SAML tracer to inspect the flow and verify that the assertion carries a matching uid attribute and acceptable NameID format 26 67.

Rollback

Select the Unsuccessful test radio button in Control Hub to keep SSO disabled 2.

Step 8 Activate SSO for the initial IdP

One IdP for every user

Do

After a passing test, select the Successful test radio button in Control Hub to activate SSO, as the configuration does not take effect unless this option is chosen 2. Note that configuring the first IdP automatically adds a routing rule set as the Default rule 11.

Verify

Confirm on the Identity provider tab that SSO is marked active and the Default routing rule appears on the Routing rules tab 11. Test a normal user sign-in from a private browser window 62.

Rollback

Deactivate SSO on the Identity provider tab 10. Users without a Webex password must reset it or an administrator must send an email for them to set one 10.

Several IdPs, with routing rules by domain or group

Do

After completing a passing test, select the Successful test radio button in Control Hub to activate the IdP 2. This initial IdP is automatically assigned to the Default routing rule 11. Note that while another IdP can later be designated as the default, the Default rule itself cannot be deactivated or deleted 11.

Verify

Verify on the Identity provider tab that the IdP is active and is referenced by the Default rule on the Routing rules tab 11.

Rollback

Deactivate SSO on the Identity provider tab, noting that this action deactivates SSO for all configured IdPs across the organization 8. Affected users without passwords must reset or establish new passwords 10.

Step 9 Add additional IdPs and define routing rules

One IdP for every user

Do

No additional action is required, as a single IdP deployment relies on the automatically created Default rule 11.

Verify

Confirm under Management > Security > Authentication > Routing rules that only the Default rule is listed 11 49.

Rollback

Suggested rollback: No configuration rollback is needed for single IdP routing rules.

Several IdPs, with routing rules by domain or group

Do

For each additional identity provider, repeat the wizard configuration from Activate SSO on the Identity provider tab 1. Note that the multiple-IdP feature supports IdPs of type SAML, OpenID Connect, or Webex Identity, but Webex supports only 1 IdP for each authentication request 37 47. Configure a routing rule by email domain or group membership on the Routing rules tab under Management > Security > Authentication 49. For group routing, create the group in Control Hub, note its Webex group ID, and set up an IdP or directory attribute for users assigned to that group ID 27. Select the routing rule's MFA configuration: keep current MFA status, override current MFA status, or allow MFA for this rule only 50. Do not skip the routing rule step, because skipping it leaves the additional IdP added but not activated 55. Adjust the priority order of routing rules if multiple overlapping rules exist 51.

Verify

Verify that each configured IdP shows as active on the Identity provider tab and that its corresponding routing rule appears in the intended priority order on the Routing rules tab 51. Test sign-in using private browser windows for accounts matching each domain or group rule 62.

Rollback

Deactivate or delete the routing rule, ensuring another active rule exists for the IdP before deactivation if users still rely on it 9. Deactivate or delete an IdP's routing rules before deleting the IdP itself 12.

Step 10 Enable certificate expiry alerts

Do

In Control Hub, go to Manage > All rules and enable the alert rules for SSO IDP Certificate expiry and SSO SP Certificate expiry 3. Configure alerts for delivery by email, to a Webex space, or both 3.

Verify

Verify that both alert rules are enabled in the alert center, noting that Webex sends expiry alerts at 60, 45, 30, and 15 days before certificate expiry and stops after renewal 4.

Rollback

Disable the alert rules under Manage > All rules 3, noting that certificate expiration risks users losing access to Webex services 5 69.

Step 11 Renew the Webex SP certificate

One IdP for every user

Do

On the Identity provider tab in Control Hub, navigate to Review certificates and expiry date and click Renew certificate 60. Download the new Webex metadata, upload it to your IdP, and then confirm renewal in Control Hub 60. If your IdP supports only a single certificate, renew during scheduled downtime because new sign-ins briefly fail while existing sessions are preserved 61.

Verify

Confirm that the new SP certificate expiration date appears in Control Hub and test user sign-in from a private browser window 62 60.

Rollback

Suggested rollback: If sign-in fails and the certificate cannot be restored, use the administrative recovery process to access Control Hub and update settings.

Several IdPs, with routing rules by domain or group

Do

Navigate to Review certificates and expiry date under the Identity provider tab and click Renew certificate 60. Download the new SP metadata and upload it to all IdPs configured across the organization before confirming in Control Hub 59. For any IdP that supports only a single certificate, perform the upload during scheduled downtime 61.

Verify

Verify that the updated SP certificate expiration date is reflected in Control Hub and validate sign-in across each IdP routing path using private browser windows 62 60.

Rollback

Suggested rollback: If authentication fails, access the portal via self-recovery procedures to review and update SAML configuration.

Step 12 Renew and update the IdP signing certificate

Microsoft Entra ID

Do

Note that Microsoft Entra ID generates a self-signed SAML signing certificate valid for 3 years and sends expiry notifications 60, 30, and 7 days prior to expiry 20 18. In Entra ID, create a new certificate with an overlapping date under SAML Signing Certificate, activate it (using a downtime interval if the app handles only 1 certificate), and download the new Federation Metadata XML 19. In Control Hub, go to the Identity provider tab, select Upload IdP metadata, run Test SSO Update, and save 28 68. Note that the change may take up to 24 hours to take effect 28.

Verify

Verify that the new IdP certificate expiration date is displayed in Control Hub and verify sign-in functionality in a private browser window 62 28.

Rollback

Make the previous certificate active again in Entra ID and re-upload the previous metadata to Control Hub while that certificate remains valid 19 28.

Okta

Do

In the Okta admin portal on the Webex app's Sign On tab, select Generate new certificate, activate it, and download the new metadata 42. In Control Hub, open the Identity provider tab, select Upload IdP metadata, select Less secure (as Okta metadata is unsigned), run Test SSO Update, and save 28 45 68. Note that the update may take up to 24 hours to take effect 28.

Verify

Verify user sign-in from a private browser window after applying the updated metadata 62 28.

Rollback

Activate the prior certificate on the Okta Sign On tab and re-upload its corresponding metadata in Control Hub before the certificate expires 42 28.

Another SAML 2.0 IdP

Do

In Control Hub, select Upload IdP metadata on the Identity provider tab, choose the security level (More secure for public CA signing or Less secure for self-signed), run Test SSO Update, and save 28 30 68. Note that certificate updates may take up to 24 hours to take effect 28.

Verify

Confirm that the new certificate expiration date is reflected in Control Hub and verify authentication in a private browser window 62 28.

Rollback

Re-upload the prior valid IdP metadata file in Control Hub before the previous certificate expires 28.

Step 13 Establish recovery paths and address trust anchors

Do

Ensure administrators know how to use SSO self recovery, which allows an admin to regain access to the Control Hub organization and update or disable SSO if sign-in fails 54. If your integration previously relied on trust anchors, ensure a direct IdP SAML certificate is uploaded; CVE-2026-20184 (CVSS 9.8) was a certificate validation flaw affecting only customers using trust anchors and requiring the upload of a new IdP SAML certificate 63.

Verify

Confirm on the Identity provider tab that a direct IdP certificate is uploaded and test sign-in in a private browser window 62.

Rollback

If emergency recovery is necessary, deactivate SSO on the Identity provider tab, requiring users without Webex passwords to reset or set them 10.

See also

Applicability

Applies to: Cisco Webex Control Hub, Microsoft Entra ID, and Okta Workforce Identity. Deployments: multi-tenant. Sources checked 2026-09-30.

What remains uncertain

The step-by-step SSO self recovery procedure is not covered by the sources below. Whether any numeric limit applies to the total number of configured IdPs is not covered by the sources below. How Webex resolves a user who matches more than one routing rule is not covered by the sources below. The specific meaning of Cisco's guidance regarding Entra provisioning in manual mode is not covered by the sources below.

See also

Referenced by

Sources

  1. 1
    SSO setup starts in Control Hub at Management > Security > Authentication then the Identity provider tab then Activate SSO.
    Single Sign-On Integration in Control Hub · Enable SSO steps · Checked 2026-09-30
  2. 2
    After testing the admin selects Successful test to turn on SSO or Unsuccessful test to turn it off; the SSO configuration does not take effect unless the first option is chosen.
    Configure single sign-on in Control Hub with Okta · Import the IdP metadata and enable single sign-on after a test · Checked 2026-09-30
  3. 3
    Control Hub offers SSO IDP Certificate expiry and SSO SP Certificate expiry alert rules deliverable by email or Webex space or both.
    Manage single sign-on integration in Control Hub · Manage SSO alerts · Checked 2026-09-30
  4. 4
    Webex sends SSO certificate expiry alerts every 15 days starting 60 days before expiry (days 60 45 30 and 15) and stops after renewal.
    Manage single sign-on integration in Control Hub · Manage SSO alerts · Checked 2026-09-30
  5. 5
    If an SSO certificate expires users may lose access to Webex services.
    Manage single sign-on integration in Control Hub · Renew expiring certificates · Checked 2026-09-30
  6. 6
    Choosing an SP certificate signed by a public certificate authority requires more frequent metadata updates unless the IdP vendor supports trust anchors.
    Configure single sign-on in Control Hub with Microsoft Entra ID · Download the Webex metadata to your local system · Checked 2026-09-30
  7. 7
    Choosing the Self-signed by Cisco SP certificate is Cisco's recommendation and means renewing it once every five years.
    Configure single sign-on in Control Hub with Microsoft Entra ID · Download the Webex metadata to your local system · Checked 2026-09-30
  8. 8
    Deactivate SSO on the Identity provider tab deactivates SSO for all configured IdPs in the organization.
    SSO with multiple IdPs in Webex · Deactivate SSO · Checked 2026-09-30
  9. 9
    Before deactivating a routing rule Cisco recommends having another active routing rule for that IdP to avoid SSO sign-in problems.
    SSO with multiple IdPs in Webex · Manage routing rules (Deactivate) · Checked 2026-09-30
  10. 10
    After SSO is deactivated users without a Webex password must reset it or the admin must send an email for them to set one.
    Manage single sign-on integration in Control Hub · Disable single sign-on · Checked 2026-09-30
  11. 11
    Configuring the first IdP automatically adds a routing rule set as the Default rule; another IdP can be made the default but the Default rule cannot be deactivated or deleted.
    SSO with multiple IdPs in Webex · Set up routing rules; Manage routing rules · Checked 2026-09-30
  12. 12
    Cisco recommends deactivating or deleting an IdP's routing rules before deleting the IdP.
    SSO with multiple IdPs in Webex · Manage IdPs (Delete) · Checked 2026-09-30
  13. 13
    If the organization uses Directory Connector then all users must be provisioned with Directory Connector when using multiple IdPs.
    SSO with multiple IdPs in Webex · Limitations · Checked 2026-09-30
  14. 14
    Cisco says not to test the SSO integration from the identity provider interface; test from Control Hub instead.
    Configure single sign-on in Control Hub with Microsoft Entra ID · Import the IdP metadata and enable single sign-on after a test · Checked 2026-09-30
  15. 15
    After a domain is claimed new users who sign up with that domain join the organization and a domain can only be claimed if it is verified in a single organization.
    Manage your domains · Claim a domain · Checked 2026-09-30
  16. 16
    A domain is verified in Control Hub under Management > Organization Settings > Domains by adding a Webex verification token to the domain's DNS TXT record and clicking Verify.
    Manage your domains · Add and verify a domain · Checked 2026-09-30
  17. 17
    The admin assigns users or groups to the Entra Webex app and downloads the Federation Metadata XML from the SAML Signing Certificate section for import into Control Hub.
    Configure single sign-on in Control Hub with Microsoft Entra ID · Configure SSO application settings in Entra ID · Checked 2026-09-30
  18. 18
    Microsoft Entra ID emails notifications 60 and 30 and 7 days before a SAML certificate expires to up to five configured addresses.
    Tutorial: Manage federation certificates · Add email notification addresses for certificate expiration · Checked 2026-09-30
  19. 19
    To renew an Entra SAML certificate the admin creates a new certificate with an overlapping date on the SAML Signing Certificate page and uploads it to the application and uses Make certificate active; if the app handles only one certificate a downtime interval is needed.
    Tutorial: Manage federation certificates · Renew a certificate that is set to expire soon · Checked 2026-09-30
  20. 20
    Microsoft Entra ID generates a self-signed SAML signing certificate valid for three years when SAML sign-on is configured for a gallery app.
    Tutorial: Manage federation certificates · Autogenerated certificate for gallery and non-gallery applications · Checked 2026-09-30
  21. 21
    The Cisco Entra ID article lists three supported NameID formats: SAML 2.0 transient and SAML 1.1 unspecified and SAML 1.1 emailAddress.
    Configure single sign-on in Control Hub with Microsoft Entra ID · Integrate Control Hub with Microsoft Entra ID (NameID formats) · Checked 2026-09-30
  22. 22
    In Microsoft Entra ID the admin opens the Webex application added or created from the application gallery and configures its SAML single sign-on with the Control Hub metadata file.
    Configure single sign-on in Control Hub with Microsoft Entra ID · Configure SSO application settings in Entra ID · Checked 2026-09-30
  23. 23
    Existing Webex customers with previous federation configurations may hit issues with the standard Entra ID Webex template because of SAML attribute changes.
    Configure single sign-on in Control Hub with Microsoft Entra ID · Integrate Control Hub with Microsoft Entra ID · Checked 2026-09-30
  24. 24
    Cisco's Entra ID SSO article states that in Entra ID provisioning is only supported in manual mode.
    Configure single sign-on in Control Hub with Microsoft Entra ID · Integrate Control Hub with Microsoft Entra ID · Checked 2026-09-30
  25. 25
    In the Entra Basic SAML Configuration the admin copies the Reply URL value into the Sign on URL field and saves.
    Configure single sign-on in Control Hub with Microsoft Entra ID · Configure SSO application settings in Entra ID · Checked 2026-09-30
  26. 26
    To troubleshoot Entra ID integration Cisco says to use a SAML tracer to verify the NameID format and that the assertion has a uid attribute matching a Webex user.
    Configure single sign-on in Control Hub with Microsoft Entra ID · Troubleshoot Entra ID integration · Checked 2026-09-30
  27. 27
    For group routing Cisco says to create a group in Control Hub and note its Webex group ID then set up an IdP or directory attribute for users assigned to that group ID.
    SSO with multiple IdPs in Webex · Set up routing rules (group attribute) · Checked 2026-09-30
  28. 28
    A renewed IdP certificate is applied by uploading new IdP metadata on the Identity provider tab and running Test SSO Update; the change may take up to 24 hours to take effect.
    Manage single sign-on integration in Control Hub · Renew an IdP certificate · Checked 2026-09-30
  29. 29
    The IdP metadata imported into Webex must identify the IdP entity ID and signing certificate and NameID format and SSO service URL.
    Single Sign-On Integration in Control Hub · IdP metadata · Checked 2026-09-30
  30. 30
    When importing IdP metadata the admin chooses More secure if the metadata is signed by a public CA or Less secure if it is self-signed.
    Manage single sign-on integration in Control Hub · Renew an IdP certificate; Upload IdP metadata to Webex · Checked 2026-09-30
  31. 31
    JIT configuration requires that the domains have already been verified and are claimed and turned on.
    SSO with multiple IdPs in Webex · Set up SAML integration (Just In Time settings prerequisites) · Checked 2026-09-30
  32. 32
    The SAML wizard's JIT settings can create or activate a user when no active user is found and can update an existing user's attributes from mapped SAML attributes.
    SSO with multiple IdPs in Webex · Set up SAML integration (Just In Time settings) · Checked 2026-09-30
  33. 33
    If Webex Meetings sites are not managed in Control Hub a separate SSO integration is required for them.
    Configure single sign-on in Control Hub with Okta · Before you begin · Checked 2026-09-30
  34. 34
    Microsoft Learn's Cisco Webex Meetings Entra tutorial configures SSO in Webex Site Administration under Common Site Settings > SSO Configuration rather than in Control Hub.
    Configure Cisco Webex Meetings for Single sign-on with Microsoft Entra ID · Configure Cisco Webex Meetings SSO · Checked 2026-09-30
  35. 35
    Setting up multiple IdPs requires the Full Admin role in Control Hub and routing-rule behaviour should be planned beforehand.
    SSO with multiple IdPs in Webex · Prerequisites · Checked 2026-09-30
  36. 36
    Webex lets an organization set up SSO with multiple IdPs and uses routing rules to decide which IdP to send each user to.
    SSO with multiple IdPs in Webex · Overview · Checked 2026-09-30
  37. 37
    The multiple-IdP feature supports IdPs of type SAML or OpenID Connect or Webex Identity.
    SSO with multiple IdPs in Webex · Limitations · Checked 2026-09-30
  38. 38
    Cisco's SSO prerequisites say to configure the NameID Format as urn:oasis:names:tc:SAML:2.0:nameid-format:transient.
    Single Sign-On Integration in Control Hub · Prerequisites · Checked 2026-09-30
  39. 39
    Without Single Logout configured an existing IdP session remains valid after the user signs out of Webex and a warning displays on sign-out.
    Manage single sign-on integration in Control Hub · Understand Single Logout · Checked 2026-09-30
  40. 40
    In the Okta admin portal the admin adds the Cisco Webex application from Applications > Add Application and selects SAML 2.0.
    Configure single sign-on in Control Hub with Okta · Configure the Okta application · Checked 2026-09-30
  41. 41
    Users and groups must be assigned to the Okta Webex app or the Control Hub and Okta integration will not work.
    Configure single sign-on in Control Hub with Okta · Configure the Okta application (Assignments) · Checked 2026-09-30
  42. 42
    Okta SAML signing certificates are managed on the app integration's Sign On tab where an admin can Generate new certificate and Activate a certificate.
    Manage signing certificates · Manage signing certificates (page body) · Checked 2026-09-30
  43. 43
    Webex supports three NameID formats and uses the first NameID entry listed in the IdP metadata.
    Configure single sign-on in Control Hub with Okta · Configure the Okta application (NameID format note) · Checked 2026-09-30
  44. 44
    Cisco's Okta procedure sets the app to not display the application icon to users or in the Okta Mobile App.
    Configure single sign-on in Control Hub with Okta · Configure the Okta application · Checked 2026-09-30
  45. 45
    Because Okta does not sign its metadata the admin selects Less secure when importing Okta metadata into Control Hub.
    Configure single sign-on in Control Hub with Okta · Import the IdP metadata and enable single sign-on after a test · Checked 2026-09-30
  46. 46
    For Okta the admin copies the entityID and the AssertionConsumerService location from the Webex metadata file into the Okta app's advanced SAML settings.
    Configure single sign-on in Control Hub with Okta · Download the Webex metadata to your local system; Configure the Okta application · Checked 2026-09-30
  47. 47
    Webex supports only one IdP for each authentication request.
    Configure single sign-on in Control Hub with Microsoft Entra ID · Integrate Control Hub with Microsoft Entra ID · Checked 2026-09-30
  48. 48
    An organization that picks a public-CA-signed SP certificate should expect to repeat the SP metadata upload to its IdP more often than one using the Cisco self-signed certificate.inferred
    Configure single sign-on in Control Hub with Microsoft Entra ID · Download the Webex metadata to your local system · Checked 2026-09-30
  49. 49
    Routing rules can route users to an IdP by email domain or by group membership and are managed on the Routing rules tab under Management > Security > Authentication.
    SSO with multiple IdPs in Webex · Set up routing rules · Checked 2026-09-30
  50. 50
    Each routing rule offers MFA choices: keep current MFA status or override current MFA status or allow MFA for this rule only.
    SSO with multiple IdPs in Webex · Set up routing rules (MFA) · Checked 2026-09-30
  51. 51
    Admins can change the priority order of routing rules when rules exist for multiple IdPs.
    SSO with multiple IdPs in Webex · Manage routing rules · Checked 2026-09-30
  52. 52
    For SSO with Control Hub the identity provider must conform to the SAML 2.0 specification.
    Single Sign-On Integration in Control Hub · Prerequisites · Checked 2026-09-30
  53. 53
    In the SAML wizard an admin can rename the SAML attribute used for Webex username or primary email from uid to a name agreed with the IdP owner such as email or upn.
    SSO with multiple IdPs in Webex · Set up SAML integration (SAML mapping) · Checked 2026-09-30
  54. 54
    If SSO sign-in fails an admin can use the SSO self recovery option to regain access to the Control Hub-managed organization and update or disable SSO.
    SSO with multiple IdPs in Webex · Additional information (SSO self recovery) · Checked 2026-09-30
  55. 55
    If the routing rule step is skipped for an additional IdP Control Hub adds the IdP but does not activate it.
    SSO with multiple IdPs in Webex · Set up SAML integration (routing rule step) · Checked 2026-09-30
  56. 57
    Control Hub SSO supports only service-provider-initiated (SP-initiated) flows.
    Configure single sign-on in Control Hub with Okta · Import the IdP metadata and enable single sign-on after a test · Checked 2026-09-30
  57. 58
    The Webex service provider metadata file downloaded from Control Hub is named idb-meta-<org-ID>-SP.xml.
    Single Sign-On Integration in Control Hub · Webex metadata · Checked 2026-09-30
  58. 59
    With multiple IdPs Cisco recommends uploading the renewed SP metadata to all IdPs in the organization.
    SSO with multiple IdPs in Webex · Manage IdPs (Renew SP certificate) · Checked 2026-09-30
  59. 60
    The SP certificate is renewed from the Identity provider tab via Review certificates and expiry date then Renew certificate then downloading the new Webex metadata and uploading it to the IdP before confirming in Control Hub.
    Manage single sign-on integration in Control Hub · Renew a Webex Service Provider (SP) certificate · Checked 2026-09-30
  60. 61
    If the IdP supports only a single certificate Cisco recommends renewing the SP certificate during scheduled downtime because new sign-ins briefly fail while existing sign-ins are preserved.
    Manage single sign-on integration in Control Hub · Renew a Webex Service Provider (SP) certificate · Checked 2026-09-30
  61. 62
    Test SSO setup opens IdP authentication in a new tab and Cisco recommends copying the test URL into a private browser window to avoid cached sign-in data.
    SSO with multiple IdPs in Webex · Test SSO · Checked 2026-09-30
  62. 63
    CVE-2026-20184 (CVSS 9.8) was an SSO certificate validation flaw in Webex Services that affected only customers using trust anchors and required them to upload a new IdP SAML certificate to Control Hub.
    Cisco Webex Services Certificate Validation Vulnerability · Summary; Affected Products; Workarounds · Checked 2026-09-30
  63. 64
    Cisco's SSO management article states that SSO trust anchors will be removed on May 22 2026 and that orgs should upload a new certificate before that date.
    Manage single sign-on integration in Control Hub · Notice at top of article (trust anchors) · Checked 2026-09-30
  64. 65
    For standard SSO the IdP must send a uid attribute mapped to the user's email address or User-Principal-Name; Partner SSO uses the mail attribute instead.
    Single Sign-On Integration in Control Hub · Prerequisites (required attributes) · Checked 2026-09-30
  65. 66
    Webex supports mapping up to five email addresses to the uid and the IdP must match one user email address to the uid at sign-in.
    Single Sign-On Integration in Control Hub · Prerequisites (required attributes) · Checked 2026-09-30
  66. 67
    For SSO troubleshooting, Cisco recommends the SAML tracer add-on for Firefox, Chrome or Edge to inspect the SAML flow.
    Single Sign-On Integration in Control Hub · Single Sign-On Integration in Control Hub > Troubleshooting · Checked 2026-09-30
  67. 68
    When updating SSO metadata, Cisco recommends running Test SSO Update and checking the sign-in experience in a private browser window so cached information does not interfere.
    Manage single sign-on integration in Control Hub · Manage single sign-on integration in Control Hub > update metadata / test · Checked 2026-09-30
  68. 69
    If an SSO certificate expires, users may lose access to Webex services.
    Manage single sign-on integration in Control Hub · Manage single sign-on integration in Control Hub > certificate renewal · Checked 2026-09-30

Documents

tier 2 current vendor documentation

Cisco Webex Services Certificate Validation Vulnerability

Cisco PSIRT · 2026-04-16 · accessed 2026-09-30

tier 2 current vendor documentation

Configure Cisco Webex Meetings for Single sign-on with Microsoft Entra ID

Microsoft · 2026-05-26 · accessed 2026-09-24

tier 2 current vendor documentation

Configure single sign-on in Control Hub with Microsoft Entra ID

Cisco Webex · 2026-07-30 · accessed 2026-09-24

tier 2 current vendor documentation

Configure single sign-on in Control Hub with Okta

Cisco · 2025-10-21 · accessed 2026-09-30

tier 2 current vendor documentation

Manage signing certificates

Okta · 2026-09-30 · accessed 2026-09-30

tier 2 current vendor documentation

Manage single sign-on integration in Control Hub

Cisco · 2026-09-10 · accessed 2026-09-30

tier 2 current vendor documentation

Manage single sign-on integration in Control Hub

Cisco Systems (Webex Help Center) · 2026-09-10 · accessed 2026-09-30

tier 2 current vendor documentation

Manage your domains

Cisco · 2026-09-29 · accessed 2026-09-30

tier 2 current vendor documentation

Single Sign-On Integration in Control Hub

Cisco · 2026-09-09 · accessed 2026-09-30

tier 2 current vendor documentation

SSO with multiple IdPs in Webex

Cisco Webex · 2026-04-17 · accessed 2026-09-24

tier 2 current vendor documentation

Tutorial: Manage federation certificates

Microsoft · 2025-04-30 · accessed 2026-09-30

Cite this page

APA

WarmTransfer. (2026, September 30). Setting up SSO for a Webex organization. WarmTransfer. https://warmtransfer.net/guides/webex-control-hub-sso-setup

BibTeX

@misc{warmtransfer-webex-control-hub-sso-setup,
  title  = {Setting up SSO for a Webex organization},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/guides/webex-control-hub-sso-setup},
  note   = {Verified 2026-09-30}
}