Skip to content
Flinq Help Centre
Search help
Organisation, Users & Security

Authentication, API access and audit

How to switch SSO to another provider

Move SAML SSO to a new identity provider with a tested rollback path.

Katrin Erb Written by Katrin Erb Updated Published

Switch SAML single sign-on (SSO) providers in a controlled change window so users are not locked out of Flinq.

Before you start

  • You need Organisation admin access in Flinq and administrator access to both identity providers.

  • Keep the old provider active until the new provider has been tested.

  • Confirm a password-based recovery administrator can sign in.

  • Record the current metadata URL so you can roll back.

Prepare the new provider

  1. Create the Flinq application in the new provider.

  2. Configure the exact Entity ID, ACS URL and sign-on URL for your Flinq workspace.

  3. Configure the required email and name claims.

  4. Assign a non-critical test user whose email matches their Flinq account.

  5. Confirm that the provider exposes a public HTTPS metadata URL.

Change the provider

  1. Schedule a short change window and tell users that SSO is being updated.

  2. Go to Settings > Organisation Settings.

  3. Under SSO (Single Sign-On), replace the existing Metadata URL with the new provider's URL.

  4. Save the settings.

  5. In a private browser window, sign in as the test user and confirm the correct office and permissions.

  6. Test another representative user before expanding the new assignment.

If the test fails

Sign in with the recovery administrator, restore the previous metadata URL and save. Check the workspace URLs, metadata availability, claims and user assignment in the new provider before trying again.

Complete the cutover

After representative users have signed in successfully, expand the assignment in the new provider. Keep the old configuration available for the agreed rollback period, then remove it according to your organisation's change process.

Keep reading

Related articles