Testing and Enabling SSO
Test Mode
After completing federation configuration in the Staging environment, enable Test Mode on the Identity Provider Management page.
In Test mode, federated sign‑in runs alongside username‑and‑password authentication. Select a representative group of existing Workbench users and ask them to sign in using Sign in with corporate email. Users can also sign in using the direct Workbench URL displayed on the Basic configuration page, which bypasses the Workbench login screen.
For each tester, confirm the following:
- Authentication succeeds through your identity provider.
- Users can access the same tools and features through Workbench or the appropriate gateway or portal.
If sign‑in fails, review the SAML assertion using your identity provider’s logging tools or a standard SAML tracing tool. Common issues include incorrect or non‑public metadata URLs, mismatched attribute names, unsigned assertions, or a user that has not been set up and provisioned by Surescripts support.
New User Behavior (Authentication‑Only)
In authentication‑only federation:
- Users authenticate successfully through your identity provider.
- New users are not automatically created in Workbench.
- User accounts must be provisioned by Surescripts Support before access is granted.
If a user’s email address matches multiple existing Workbench users, the user is prompted to select the correct account on first sign‑in. This selection is reused for future logins.
To add new users, submit a case to Surescripts Support using the same process you use today. Once the user is provisioned, they can sign in using federated sign‑in.
Switch to Require SSO for Your Organization
After testing is complete and the Staging environment behaves as expected, a customer federation administrator sets Enable to Require SSO on the Identity Provider Management page.
This setting is configured in the Federation settings for the environment. Enabling Require SSO disables username‑and‑password sign‑in for users signing in from your configured email domains and requires all users in the environment to authenticate through your identity provider.
Once Require SSO is enabled, every sign‑in to Workbench, the Specialty Medications Gateway, and the Prior Authorization Portal for your organization uses federated SSO.
Repeat the same sequence in Production:
- Configure federation
- Validate in Test mode
- Switch to Require SSO
Most customers move to Production shortly after passing validation in the Staging environment so that the configuration details are still up to date.
Note: Require SSO is an environment‑level setting. Enabling it affects all users in the selected environment.
Ongoing Maintenance
After federated sign‑in is enabled, your organization remains responsible for maintaining federation settings in Workbench as domains, certificates, and user populations change over time.
- Update email domains in Workbench whenever your organization’s domains change
- Rotate federation metadata by updating the metadata URL in Workbench when your identity provider publishes a new signing certificate.
- Review the user list in Workbench to audit access and view each user’s most recent login date.