Set up SAML authentication
- Updated: 2026/02/03
Switch user authentication for Control Room from Control Room database to SAML single sign-on (SSO).
Prerequisites
- SAML configuration cannot be changed to other authentication methods after it is established.
- When using SAML for authentication, use the network access capabilities of the IdP to restrict access of the Control Room to specific allowed IP addresses. Ensure all allowed IP addresses configured are removed from the Control Room network settings before switching to SAML for authentication. For more information, see Allowed IP addresses.
-
For any On-Premises Control Room configured to use Transport Layer Security (TLS) termination at the load balancer and uses HTTP to connect to Control Room nodes, additional Control Room configurations are required to forward all X-Forwarded-* headers. See A360 | Forward all X-Forwarded-* headers during TLS termination
Before setting up SAML authentication, do the following:
-
Ensure that you are logged in to the Control Room as the administrator.
- You have collected all the necessary user information in advance, such as user ID, first name, last name, and email address for the user who accesses the Control Room.
- You might need to complete setup tasks:
- Introducing credentials on a new system (creating user accounts).
- Importing users (uploading user details such as user ID, name, and email
address so they are recognized by the Control Room).Note: If you are importing users, make sure these details are consistent and identical in both Automation Anywhere and your identity provider (such as Okta when using SSO/SAML). This matching is required for users to log in after SAML integration.
- You have the SAML certificate provided by your identity provider ready for upload during the authentication setup process.
To switch the Control Room to SAML SSO, follow these steps.