This guide provides step-by-step instructions for configuring Single Sign-On (SSO) between ClassLink and your FMX application using SAML 2.0.Important: This document covers SSO configuration only. ClassLink user provisioning and directory synchronization are managed separately within ClassLink.OverviewIdentity Provider (IdP): ClassLinkService Provider (SP): FMXProtocol: SAML 2.0Once configured, users will be able to access FMX using their ClassLink credentials.PrerequisitesBefore you begin, ensure the following:You have administrator access to ClassLinkSAML SSO is enabled for your FMX tenantYou know your FMX hostname (for example: https://hostname.gofmx.com)Users who will access FMX already exist in FMX and ClassLinkFMX SAML Configuration ValuesUse the following FMX values when configuring the ClassLink SAML application:Audience / Entity IDhttps://hostname.gofmx.com/ Assertion Consumer Service (ACS) / Reply URLhttps://hostname.gofmx.com/login/saml2/callback Recipient URLhttps://hostname.gofmx.com/login/saml2/callbackStep 1: Create a SAML Application in ClassLinkLog in to the ClassLink Management ConsoleNavigate to AppsClick Add AppSearch for Custom SAML App (or equivalent)Select SAML 2.0 as the authentication typeStep 2: Configure SAML Settings in ClassLinkWhen configuring the SAML application, enter the FMX values listed above.Required SettingsEntity ID / Audience:https://hostname.gofmx.com/ACS / Reply URL:https://hostname.gofmx.com/login/saml2/callbackRecipient:https://hostname.gofmx.com/login/saml2/callbackSAML Response: SignedAssertion: Signed (recommended)NameID ConfigurationNameID Format: Email AddressNameID Value: User EmailThis ensures FMX can uniquely identify users by email address.Step 3: Configure User Attributes (Claims)FMX requires the user’s email address and recommends sending first and last name attributes.Required Attributeemail → User EmailRecommended AttributesfirstName → User First NamelastName → User Last NameAttribute names may vary based on your ClassLink environment.Step 4: Obtain RapidIdentity IdP Metadata URLAfter saving the SAML application, copy the IdP Metadata URL from ClassLink. This URL is all FMX needs to complete the SSO setup.Step 5: Configure SSO in FMXProvide the IdP Metadata URL to FMX (or FMX Support). Once this is configured, FMX will enable SAML SSO for your tenant.Step 6: Assign Users in ClassLinkEnsure users are entitled to the FMX application in ClassLink. Only entitled users will be able to log in via SSO.Step 7: Test the SSO ConfigurationWe recommend testing with a small group of users before full deployment.Test OptionsIdP-initiated login: Launch FMX from the ClassLink launchpadSP-initiated login: Log in from the FMX login page using the SSO optionIf login fails, verify:Entity ID and ACS URL match exactlyUsers are entitled to the applicationThe correct IdP Metadata URL is usedTroubleshooting TipsInvalid Audience error: Confirm the Entity ID matches FMX exactlyUser not found: Ensure the email in ClassLink matches the FMX user emailSignature validation errors: Verify the IdP Metadata URL is correctNeed Help?If you need assistance completing your ClassLink SSO setup, contact FMX Support and include:Your FMX tenant URLClassLink IdP Metadata URLAny error messages or screenshotsOnce complete, users will be able to securely access FMX using ClassLink Single Sign-On. Was this article helpful? 0 out of 0 found this helpful