Set up SAML authentication
- Updated: 2026/02/03
Switch user authentication for Control Room from Control Room database to SAML single sign-on (SSO).
Prerequisites
Note:
- SAML configuration cannot be changed to other authentication methods after it is established.
- When using SAML for authentication, use the network access capabilities of the IdP to restrict access of the Control Room to specific allowed IP addresses. Ensure all allowed IP addresses configured are removed from the Control Room network settings before switching to SAML for authentication. For more information, see 允许的 IP 地址.
-
For any On-Premises Control Room configured to use Transport Layer Security (TLS) termination at the load balancer and uses HTTP to connect to Control Room nodes, additional Control Room configurations are required to forward all X-Forwarded-* headers. See A360 | Forward all X-Forwarded-* headers during TLS termination
Before setting up SAML authentication, do the following:
-
确保您以管理员身份登录到 Control Room。
- You have collected all the necessary user information in advance, such as user ID, first name, last name, and email address for the user who accesses the Control Room.
- You might need to complete setup tasks:
- Introducing credentials on a new system (creating user accounts).
- Importing users (uploading user details such as user ID, name, and email
address so they are recognized by the Control Room).Note: If you are importing users, make sure these details are consistent and identical in both Automation Anywhere and your identity provider (such as Okta when using SSO/SAML). This matching is required for users to log in after SAML integration.
- You have the SAML certificate provided by your identity provider ready for upload during the authentication setup process.
Note: You must validate the SAML IdP setup before you configure
the Control Room. See 将 Control Room 配置为服务提供商.
To switch the Control Room to SAML SSO, follow these steps.