With single sign-on (SSO), your users can access ShareGate Migrate and ShareGate Protect without having to manage separate usernames and passwords. This article covers how to set up SAML-based SSO for your ShareGate workspace.
Before you start
You must have a ShareGate Migrate Enterprise or Protect subscription.
You need access to an identity provider (IdP) that supports SAML (Security Assertion Markup Language) 2.0.
Have your IdP's SAML metadata ready: your SSO URL, Issuer URL, and X.509 certificate.
Supported identity providers
ShareGate SSO supports a wide range of SAML 2.0 identity providers, including Okta Identity Cloud, OneLogin, JumpCloud, PING Identity, CyberArk Identity, Auth0, Frontegg, WorkOS, SecureAuth, and many more.
Things to know before you set up SSO
ShareGate only supports SAML 2.0.
ShareGate does not support Single Logout (SLO).
All authentication requests must be signed using SHA-256.
ShareGate uses service provider (SP)-initiated SAML setups for better security and compatibility with ShareGate features.
Set up SAML SSO
Create a SAML application in your identity provider. In your IdP, create a new SAML application. During setup, you'll need to enter an Assertion Consumer Service (ACS) URL and an Entity ID. Use
https://www.placeholder.comas a temporary value in both fields for now. ShareGate will provide the final values in step 3.
Send your SAML metadata to ShareGate support. Contact ShareGate support and request SAML setup for your account. Include your application's SAML metadata from step 1. At a minimum, you need to provide:
Your identity provider SSO URL
Your Issuer URL
Your X.509 certificate
Receive your ACS URL and Entity ID from ShareGate. Once the ShareGate support team finishes your setup, they'll send you:
An ACS URL
An Entity ID
The required attributes and NameID configuration for your identity provider
Add the values to your SAML application. Return to your SAML application in your IdP and replace the placeholder values with the ACS URL and Entity ID ShareGate sent you. Once complete, your users can sign in to ShareGate using their credentials from your identity provider.
