Single Sign-On (SSO)
SAML

Single Sign-On (SSO)

Let your organization's users sign in to Kensho with your identity provider (IdP) over SAML 2.0. Kensho works with any SAML 2.0 IdP.

Supported features

  • SP-initiated SSO: sign-in starts from Kensho or an application that uses your Kensho subscription.
  • IdP-initiated SSO: sign-in starts from a Kensho tile in your IdP dashboard.
  • Just-In-Time (JIT) provisioning: a matching Kensho account is created on first sign-in.

Prerequisites

To set up SAML 2.0 SSO, Kensho will need to know the following:

  • A list of your corporate email domains (for example, @example.com).
  • The email addresses of a few pilot users who will test the connection before it is opened to all your domains.
  • Whether all your users should get the same entitlements, or different users need different entitlements (see Entitlements), and if so, the distinct access levels you need (for example, analyst and admin).

Contact the Kensho support team (support@kensho.com) with this information to request SSO. Kensho provisions the connection on its side and sends you:

  • An ACS URL and Audience URI to use below.
  • If different users need different entitlements, the role names to use in the Entitlements step.

Configuration steps

Not yet published

The Kensho app isn't in the Entra Gallery yet. Use the Microsoft Entra ID (Manual) tab above to set it up manually.
  1. In the Microsoft Entra admin center, go to Entra ID → Enterprise apps and click New application.

  2. Search for and select the Kensho app, then click Create.

  3. On the app's overview page, go to Manage → Single sign-on and select SAML.

  4. Under Basic SAML Configuration, click Edit:

    • Click Add identifier and enter the Audience URI from Kensho.
    • Click Add reply URL and enter the ACS URL from Kensho.

    Leave the other fields empty and click Save.

  5. Under SAML Certificates, copy the App Federation Metadata Url.

  6. Go to Manage → Users and groups and assign the users and groups who need access to Kensho. Only assigned users can sign in. If different users need different entitlements, assign each to the matching app role here (see Entitlements).

Then complete the connection with Kensho:

  1. Send your metadata URL (or XML file) to the Kensho support team (support@kensho.com).
  2. Kensho activates the connection.

Your SAML configuration for Kensho is complete. Kensho creates each user's account on their first sign-in (JIT provisioning).

SAML attributes

Kensho reads the following attributes from the SAML assertion to create each user. Map each one to the corresponding user profile field in your IdP.

AttributeRequiredExampleDescription
emailYesjane.doe@example.comThe user's email address.
firstNameYesJaneThe user's first name.
lastNameYesDoeThe user's last name.
kenshoRolesNousers_app
users_app_admin
The user's entitlements (multi-valued). See Entitlements.

Entitlements

This is optional. If everyone should get the same entitlements, skip it: assign the relevant groups to the Kensho app in the configuration steps, and all assigned users receive the same entitlements.

For different entitlements, send the multi-valued kenshoRoles attribute that maps your IdP groups to the role names Kensho provides you.

Use app roles to emit the Kensho role names. In the Microsoft Entra admin center:

  1. Go to Entra ID → App registrations, select the Kensho app (switch to the All applications tab if it isn't listed), and open Manage → App roles.

  2. For each Kensho role name, click Create app role and enter:

    • Display name: any label that describes the entitlement.
    • Allowed member types: Users/Groups
    • Value: the Kensho-provided role name, exactly as given.
    • Description: any description.

    Leave Do you want to enable this app role? checked and click Apply.

  3. Go to Enterprise apps → the Kensho app → Users and groups and assign each user or group to the matching app role. To give a user or group more than one role, add a separate assignment per role.

  4. Go to Single sign-on → Attributes & Claims, click Edit, then Add new claim, and enter:

    • Name: kenshoRoles
    • Namespace: leave empty.
    • Source: Attribute
    • Source attribute: user.assignedroles

    Click Save. Entra now sends each assigned user's role names as a multi-valued kenshoRoles attribute.

SP-initiated SSO

  1. From your browser, navigate to kensho.okta.com (opens in a new tab), a Kensho application, or a partner application that uses your Kensho subscription.
  2. Enter your corporate email address and continue.
  3. You are redirected to your IdP, authenticate there, and are then redirected back to Kensho.

Provisioning

Kensho provisions accounts just-in-time (JIT): the first time one of your users signs in through SSO, Kensho creates their account from the attributes your IdP sends.

Automatic account syncing and deprovisioning (SCIM) is not currently supported.

Troubleshoot

For help configuring or debugging a connection, contact the Kensho support team at support@kensho.com.