---
title: "Managing Inbound SSO"
slug: "managing-inbound-sso"
updated: 2024-05-15T11:48:05Z
published: 2024-05-15T11:48:05Z
canonical: "documentation.infinite.com/managing-inbound-sso"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://documentation.infinite.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Managing Inbound SSO

Abstract

Management of Inbound SSO includes managing inbound SSO, maintaining certificates, enabling SSO for individual and multiple users, and other miscellaneous tasks.

### Refreshing a Certificate

Abstract

When a certificate is about to expire, Administrators need to refresh the certificate to avoid expiration. Refreshing a certificate requires the Administrator to add a new certificate to the existing expiring certificate. Adding a certificate in this way refreshes the existing certificate and avoids expiration.

#### Navigating to the Inbound SSO

Infinite BrassRing Platform Administrator logs in to Infinite BrassRing Platform:

- Selects the Application Launcher icon

![AugApplLauncher.jpg](https://cdn.us.document360.io/4bb62c4c-9973-48ec-ab93-23d4b1755503/Images/Documentation/9aac4492-42d5-41d1-80b1-c22ddf4e8b75.jpg)

to launch the Application Launcher navigation bar (if necessary).
- Selects the Admin action on the Infinite BrassRing Platform navigation bar. The **Administration**page opens.

![TS_AdminLogin.jpg](https://cdn.us.document360.io/4bb62c4c-9973-48ec-ab93-23d4b1755503/Images/Documentation/be09d3a5-457e-498d-aa30-5e5e7f6b9cd1.jpg)

Browses to the Admin.
- Opens hamburger menu and selects SSO → Inbound.

![July_menuInbound.jpg](https://cdn.us.document360.io/4bb62c4c-9973-48ec-ab93-23d4b1755503/Images/Documentation/2154a8c4-2e69-4f34-8ec8-8a1695ab93a3.jpg)

The **Edit Inbound SSO Configuration** page opens.

#### Adding a new Certificate

When a client identity provider system's certificate is about to expire, administrators must find the location of the expiring certificate in order to add the new certificate.

- Locates the expiring certificate and determines where the new certificate needs to be placed. For example, if it is the signing certificate that is about to expire, the new certificate needs to be placed in the slot next to the expiring signing certificate.
- Drops the new certificate into the respective slot. Copy and paste can also be used to place the new certificate.
- Selects Submit.

There are now two certificates in use simultaneously. When the existing certificate expires, it can be removed.

### Migrating Tenants to SSO

Abstract

In order for tenants to use SSO, Administrators must follow the steps outlined in Setting up SSO.

Link to [Setting up SSO](https://documentation.infinite.com/docs/setting-up-sso).

### Enabling SSO for a Single User

Abstract

Administrators can enable SSO for single users only if the tenant is set up for SSO. For additional information, see Migrating a Tenant to SSO.

> [!NOTE]
> Note
> 
> Administrators can enable SSO for single users only when the tenant is set up for SSO. For details, see [Migrating Tenants to SSO](/docs/managing-inbound-sso.html#UUID-6dfadd2c-e932-8154-caa1-1854a4e39acb).

#### Navigating to the Inbound SSO

Infinite BrassRing Platform Administrator logs in to Infinite BrassRing Platform:

- Selects the Application Launcher icon

![AugApplLauncher.jpg](https://cdn.us.document360.io/4bb62c4c-9973-48ec-ab93-23d4b1755503/Images/Documentation/9aac4492-42d5-41d1-80b1-c22ddf4e8b75.jpg)

to launch the Application Launcher navigation bar (if necessary).
- Selects the **Admin**action on the Infinite BrassRing Platform navigation bar. The **Administration**page opens.

![TS_AdminLogin.jpg](https://cdn.us.document360.io/4bb62c4c-9973-48ec-ab93-23d4b1755503/Images/Documentation/be09d3a5-457e-498d-aa30-5e5e7f6b9cd1.jpg)
- Opens hamburger menu and selects Manage Users → Search Users.

![Jul_ManUsers_SearchUsers.jpg](https://cdn.us.document360.io/4bb62c4c-9973-48ec-ab93-23d4b1755503/Images/Documentation/4e8d9556-346f-4695-a6bc-fc8fd27be6aa.jpg)

The **Search Users** page opens.
- Enters the email or name of the user in the search field.

![July_SearchUsersPage.jpg](https://cdn.us.document360.io/4bb62c4c-9973-48ec-ab93-23d4b1755503/Images/Documentation/e3717e68-7eef-4823-8a3e-21cd94113dbb.jpg)
- Edit the User Profile as needed and selects **Save and Continue.**
- Select the check box for **Enable SSO** for the user.

See [Updating an Existing User](/v1/docs/manage-users) in the Administration Application Guide for detailed information on working with user details.

### Enabling SSO for Multiple Users

Abstract

Administrators can enable SSO for multiple users only if the tenant is set up for SSO. For more information, see Migrating a Tenant to SSO. Administrators can import their users into Infinite BrassRing Platform in one of two ways. Administrators can do a direct import or temporarily enable the Consider all users eligible for SSO option for users during import process.

> [!NOTE]
> Note
> 
> Administrators can enable SSO for single users only when the tenant is set up for SSO. For more information, see [Migrating Tenants to SSO](/v1/docs/managing-inbound-sso#migrating-tenants-to-sso).

###### Importing Users into the Infinite BrassRing Platform

Administrators can import users into the Infinite BrassRing Platform by using Batch Integration or Real time Integration. See [How to Import Users](/v1/docs/user-provisioning-configuration#migrating-tenants-to-sso) for detailed instructions.

###### Batch and Real-Time Integrations

Batch Integration uses a .csv file to import users into the Infinite BrassRing Platform. Real-Time integrations use XML files and transported through a web service to an Infinite endpoint. Administrators must first export their users and then import the users into Infinite BrassRing Platform. See [How to Import Users](/v1/docs/user-provisioning-configuration#user-import-process-steps)for detailed instructions on how to use either of these methods.

###### Consider all users eligible for SSO

Depending on the number of users being imported, importing might take a long time to complete. Alternatively, Administrators can import users and enable the Consider all users eligible for SSO option during import. Using this option is a two-step process. First, users are imported with the setting Consider all users eligible for SSO and after import, users need to be added as Infinite BrassRing Platform users AND be enabled for SSO. See [How to Configure Inbound SSO](/v1/docs/user-provisioning-configuration/#how-to-configure-inbound-sso)for detailed instructions.

> [!NOTE]
> Note
> 
> The Consider all users eligible for SSO is intended only to be used temporarily.
