Source record · tier 2 current vendor documentation
Configure single sign-on in Control Hub with Microsoft Entra ID
- Publisher
- Cisco Webex
- URL
- https://help.webex.com/en-us/article/mfu88u/Configure-single-sign-on-in-Control-Hub-with-Microsoft-Entra-ID
- Published
- 2026-07-30
- Updated
- unknown
- Accessed
- 2026-09-24
- HTTP status
- 200
- License
- Cisco website terms of use; all rights reserved; no-redistribution; short excerpts and locators only
Source notes citing this source
- When downloading Webex SP metadata, Cisco recommends the Cisco self-signed certificate option, which needs renewal once every five years; a public-CA-signed option needs frequent metadata updates unless the IdP supports trust anchors. in context
- Control Hub SSO with Entra ID accepts SAML NameID formats transient (SAML 2.0), unspecified (SAML 1.1) and emailAddress (SAML 1.1). in context
- Cisco's Control Hub SSO guidance for Entra ID says only Service Provider-initiated flows are supported and SSO must not be tested from the IdP interface. disputed in context
- The SAML assertion to Webex must include a uid attribute whose value matches an existing Webex user. in context
- Before configuring SAML SSO in Control Hub, the Webex users must already exist, either created locally or synchronized from a directory. in context
- If provisioning sets Webex userName from userPrincipalName but the SAML uid claim is sourced from user.mail, users whose mail differs from their UPN are likely to fail SSO matching. inferred in context
- Choosing an SP certificate signed by a public certificate authority requires more frequent metadata updates unless the IdP vendor supports trust anchors. in context
- Choosing the Self-signed by Cisco SP certificate is Cisco's recommendation and means renewing it once every five years. in context
- Cisco says not to test the SSO integration from the identity provider interface; test from Control Hub instead. in context
- The admin assigns users or groups to the Entra Webex app and downloads the Federation Metadata XML from the SAML Signing Certificate section for import into Control Hub. in context
- The Cisco Entra ID article lists three supported NameID formats: SAML 2.0 transient and SAML 1.1 unspecified and SAML 1.1 emailAddress. in context
- In Microsoft Entra ID the admin opens the Webex application added or created from the application gallery and configures its SAML single sign-on with the Control Hub metadata file. in context
- Existing Webex customers with previous federation configurations may hit issues with the standard Entra ID Webex template because of SAML attribute changes. in context
- Cisco's Entra ID SSO article states that in Entra ID provisioning is only supported in manual mode. in context
- In the Entra Basic SAML Configuration the admin copies the Reply URL value into the Sign on URL field and saves. in context
- To troubleshoot Entra ID integration Cisco says to use a SAML tracer to verify the NameID format and that the assertion has a uid attribute matching a Webex user. in context
- Webex supports only one IdP for each authentication request. in context
- An organization that picks a public-CA-signed SP certificate should expect to repeat the SP metadata upload to its IdP more often than one using the Cisco self-signed certificate. inferred in context
Cite this source record
APA
WarmTransfer. (2026, July 30). Configure single sign-on in Control Hub with Microsoft Entra ID. WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-help-mfu88u-sso-entra-id
BibTeX
@misc{warmtransfer-cisco-help-mfu88u-sso-entra-id,
title = {Configure single sign-on in Control Hub with Microsoft Entra ID},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/cisco-help-mfu88u-sso-entra-id},
note = {Cisco Webex, accessed 2026-09-24}
}