Source record · tier 2 current vendor documentation
SSO with multiple IdPs in Webex
- Publisher
- Cisco Webex
- URL
- https://help.webex.com/en-us/article/ngp4sr8/SSO-with-multiple-IdPs-in-Webex
- Published
- 2026-04-17
- Updated
- unknown
- Accessed
- 2026-09-24
- HTTP status
- 200
- License
- Cisco website terms of use; all rights reserved; no-redistribution; short excerpts and locators only
Source notes citing this source
- If an organization uses Directory Connector, all users must be provisioned through Directory Connector when multi-IdP SSO is configured, and SAML JIT provisioning cannot remove users from groups or delete users. in context
- The first IdP configured automatically gets the Default routing rule, which cannot be deactivated or deleted, although its routed IdP can be changed. in context
- The Webex multi-IdP configuration supports SAML, OpenID Connect and Webex Identity as identity provider types, and requires the Full Admin role in Control Hub. in context
- Webex multi-IdP SSO routes users to identity providers through routing rules configured by domain or group membership. in context
- Deactivate SSO on the Identity provider tab deactivates SSO for all configured IdPs in the organization. in context
- Before deactivating a routing rule Cisco recommends having another active routing rule for that IdP to avoid SSO sign-in problems. in context
- Configuring the first IdP automatically adds a routing rule set as the Default rule; another IdP can be made the default but the Default rule cannot be deactivated or deleted. in context
- Cisco recommends deactivating or deleting an IdP's routing rules before deleting the IdP. in context
- If the organization uses Directory Connector then all users must be provisioned with Directory Connector when using multiple IdPs. in context
- For group routing Cisco says to create a group in Control Hub and note its Webex group ID then set up an IdP or directory attribute for users assigned to that group ID. in context
- JIT configuration requires that the domains have already been verified and are claimed and turned on. in context
- The SAML wizard's JIT settings can create or activate a user when no active user is found and can update an existing user's attributes from mapped SAML attributes. in context
- Setting up multiple IdPs requires the Full Admin role in Control Hub and routing-rule behaviour should be planned beforehand. in context
- Webex lets an organization set up SSO with multiple IdPs and uses routing rules to decide which IdP to send each user to. in context
- The multiple-IdP feature supports IdPs of type SAML or OpenID Connect or Webex Identity. in context
- Routing rules can route users to an IdP by email domain or by group membership and are managed on the Routing rules tab under Management > Security > Authentication. in context
- Each routing rule offers MFA choices: keep current MFA status or override current MFA status or allow MFA for this rule only. in context
- Admins can change the priority order of routing rules when rules exist for multiple IdPs. in context
- In the SAML wizard an admin can rename the SAML attribute used for Webex username or primary email from uid to a name agreed with the IdP owner such as email or upn. in context
- If SSO sign-in fails an admin can use the SSO self recovery option to regain access to the Control Hub-managed organization and update or disable SSO. in context
- If the routing rule step is skipped for an additional IdP Control Hub adds the IdP but does not activate it. in context
- With multiple IdPs Cisco recommends uploading the renewed SP metadata to all IdPs in the organization. in context
- Test SSO setup opens IdP authentication in a new tab and Cisco recommends copying the test URL into a private browser window to avoid cached sign-in data. in context
Cite this source record
APA
WarmTransfer. (2026, April 17). SSO with multiple IdPs in Webex. WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-help-ngp4sr8-sso-multiple-idps
BibTeX
@misc{warmtransfer-cisco-help-ngp4sr8-sso-multiple-idps,
title = {SSO with multiple IdPs in Webex},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/cisco-help-ngp4sr8-sso-multiple-idps},
note = {Cisco Webex, accessed 2026-09-24}
}