TABLE OF CONTENTS


Follow these simple steps to set up an SSO with JumpCloud:


JumpCloud Settings


In the Admin Portal:


Add User Group


1. Open the User Groups tab and press Add button:



2. Enter the Name and press Save:


Add new User


1. Open the Users tab → press Add button → select Manual user entry: 



2. Fill in the required fields on the Details tab.


The Company Email field in JumpCloud must match the Email Address in Precoro.


3. On the User Groups tab, select the created group.


4. Activate the User and press Save user:



SSO Settings


1. Open your JumpCloud account → open the SSO tab → press the Add button:



2. Select the Custom SAML App option:


3. Configure the New Application:

  • On the General Info tab, fill in the Display Label.
  • On the SSO tab, fill in the following:


1. IdP Entity ID: enter any value (for example, "JumpCloud5").

2. SP Entity ID: →  Entity ID (from https://precoro.com/backoffice)

3. ACS URL: → Assertion Consumer Service (ACS) (from https://precoro.com/backoffice/saml/login_check)


4. SP Certificate: download the certificate from Step 1: Download the Certificate on the SSO Settings page in Precoro and upload it into SP Certificate:



5. Enable the Sign Assertion and Declare Redirect Endpoint options:



  • On the User Groups tab, select the created group and press the activate button below:


  • Select the created application and download the JumpCloud Metadata by clicking Export Metadata.


Precoro Settings


On the SSO Settings page, fill in the following:


1. STEP 3: Identity Provider Issuer → IdP Entity ID.

2. STEP 4: Upload Metadata → input the Metadata you have downloaded from JumpCloud.

3. Press the Update button.




Troubleshooting


If, during the creation of the Custom SAML App in JumpCloud you have skipped step 5 of the instruction: Enable the Sign Assertion and Declare Redirect Endpoint options. You may have problems logging in through Precoro "Company Login" (seeing the 404 error).


In that case, you should:


1. Enable Sign Assertion and Declare Redirect Endpoint options → Press save.

2. Export new Metadata (by clicking on the Export Metadata button).

3. On the SSO Settings page in Precoro, insert the new Metadata and click Update.