Source record · tier 2 current vendor documentation
Single Sign-On Integration in Control Hub
- Publisher
- Cisco
- URL
- https://help.webex.com/en-us/article/lfu88u/Single-Sign-On-Integration-in-Cisco-Webex-Control-Hub
- Published
- 2026-09-09
- Updated
- unknown
- Accessed
- 2026-09-30
- HTTP status
- 200
- License
- Cisco website terms of use; no-redistribution; short excerpts and locators only
Source notes citing this source
- SSO setup starts in Control Hub at Management > Security > Authentication then the Identity provider tab then Activate SSO. in context
- The IdP metadata imported into Webex must identify the IdP entity ID and signing certificate and NameID format and SSO service URL. in context
- Cisco's SSO prerequisites say to configure the NameID Format as urn:oasis:names:tc:SAML:2.0:nameid-format:transient. in context
- For SSO with Control Hub the identity provider must conform to the SAML 2.0 specification. in context
- Cisco recommends including Single Logout in the metadata configuration so user tokens are invalidated at both the IdP and the SP. in context
- The Webex service provider metadata file downloaded from Control Hub is named idb-meta-<org-ID>-SP.xml. in context
- For standard SSO the IdP must send a uid attribute mapped to the user's email address or User-Principal-Name; Partner SSO uses the mail attribute instead. in context
- Webex supports mapping up to five email addresses to the uid and the IdP must match one user email address to the uid at sign-in. in context
Cite this source record
APA
WarmTransfer. (2026, September 9). Single Sign-On Integration in Control Hub. WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-help-lfu88u-sso-integration-control-hub-b
BibTeX
@misc{warmtransfer-cisco-help-lfu88u-sso-integration-control-hub-b,
title = {Single Sign-On Integration in Control Hub},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/cisco-help-lfu88u-sso-integration-control-hub-b},
note = {Cisco, accessed 2026-09-30}
}