Skip to main content

SAML

SAML lets an organization use its identity provider to authenticate people to Files.com. When the same identity provider serves several sites or environments, the application configuration determines which sign-in responses each site trusts. Separate site hostnames alone do not establish separate SAML applications.

Provider Trust and Site Selection

The identity provider sends a SAML response containing an assertion about the person it authenticated. Files.com verifies the signature against the signing certificate configured for the site's SAML provider and checks the issuer against that provider's configured issuer. These settings come from the IdP metadata or the certificate fingerprint and issuer entered by the administrator.

Files.com uses Relay State to select the site whose SAML providers evaluate the response. For an IdP-initiated login, the IdP's application supplies that site's hostname. Relay State routes the response; it does not prove that the signed assertion was issued for that site. Changing the display name of a provider likewise does not change which issuer, certificate, or audience it trusts.

Entity IDs and Audiences

The provider's Entity ID is https://app.files.com/saml/metadata when no Unique Identifier is configured. With a Unique Identifier, it is https://app.files.com/saml/metadata/<Unique Identifier>. The identifier is an administrator-selected suffix; Files.com does not derive it automatically from the site's hostname.

An assertion's audience identifies the application for which the IdP issued it. When audience values are present, at least one must exactly match the Files.com provider's Entity ID. An assertion addressed only to another Entity ID fails that check, even if its signature and issuer are trusted.

Files.com accepts an assertion with no audience restriction or no nonempty audience value without requiring an audience match. If several audiences are supplied, one matching value is sufficient. Distinct Entity IDs therefore separate assertions only when the IdP restricts each assertion to the intended application's audience. They do not independently require the IdP to include that restriction.

One Identity Provider for Multiple Sites

Configure a separate application in the IdP for each Files.com site, with a distinct Entity ID and assertions restricted to that application's audience. Set each application's Relay State to the corresponding site. This allows the organization to keep one identity provider while making application assignments and sign-in requirements specific to each site. The SAML setup guidance gives the configuration values, including how to enter the Unique Identifier.

Files.com does not reject a SAML provider merely because another site's provider uses the same settings. If two sites trust the same issuer and signing certificate and use the same Entity ID, an otherwise valid assertion for that Entity ID can pass either provider's SAML validation. Different site names, application display names, or Relay State values do not make those trust settings distinct.

Account and Sign-In Requirements

Passing SAML validation does not by itself complete a login or grant permissions. Files.com matches the identity to a user on the selected site, with Just-in-Time provisioning available when configured. The user's assigned SSO provider must match the provider that validated the response. The user and provider must be enabled, and the applicable sign-in requirements, including Files.com two-factor authentication when required, still apply.

Files.com checks the assertion's validity period and prevents an assertion already consumed for sign-in from being used again. Matching provider settings on two sites does not allow the same consumed assertion to complete another sign-in. A new sign-in requires a fresh assertion from the IdP.

After authentication, the user's Files.com permissions determine access. SAML authentication does not transfer another site's account or permissions to the selected site.