If your organization uses a Firstup vanity URL and SAML single sign-on (SSO), an additional configuration is required for users to sign in to Firstup from the Microsoft Teams desktop app.
Without this configuration, users may successfully authenticate with your identity provider but then see a blank window and be unable to complete sign-in. This issue affects the Teams desktop app; sign-in may continue to work in a web browser or the Teams web app.
These instructions apply to SAML identity providers such as Okta and Microsoft Entra ID.
Before you begin
You must coordinate this change with Firstup. Firstup must update your community’s configuration at the same time that you update the SAML reply URL in your identity provider.
Contact Firstup Support to:
- Confirm the correct reply/Assertion Consumer Service (ACS) URL for your community.
- Arrange a time to update your identity provider and Firstup configuration together.
- Plan how to roll back the change if necessary.
Do not update your identity provider before Firstup confirms that it is ready to make the corresponding configuration change.
Determine your reply/ACS URL
The reply/ACS URL must use Firstup’s core address for the region where your community is hosted, rather than your vanity URL.
| Region | Reply / ACS URL Pattern |
|---|---|
| US1 | https://advocate.socialchorus.com/<brand>/<program>/saml/acs |
| US2 | https://advocate.us2.onfirstup.com/<brand>/<program>/saml/acs |
| EU | https://advocate.onfirstup.eu/<brand>/<program>/saml/acs |
Firstup Support will provide the complete URL containing the correct <brand> and <program> values for your community.
Update your identity provider
At the agreed time:
- Open the SAML application used to authenticate users to Firstup in your identity provider.
- Locate the Reply URL, ACS URL, or Single sign-on URL setting. The name varies by identity provider.
- Add the core Firstup reply/ACS URL provided by Firstup Support.
- If your identity provider supports multiple reply URLs, add the core URL and retain the existing vanity URL. This option provides the simplest rollback.
- If your identity provider supports only one reply URL, replace the vanity URL with the core URL. Make this change only during the agreed change window.
- Save the change.
- Notify Firstup Support so that Firstup can enable the corresponding configuration for your community.
Note: Important: Change only the reply/ACS URL ending in /saml/acs. Do not change the Audience, Entity ID, or Identifier URL ending in /saml/metadata. The Audience or Entity ID must continue to use your vanity URL.
Test the configuration
After both changes are complete, confirm that a user can sign in to Firstup through:
- A supported web browser.
- The Microsoft Teams web app.
- The Microsoft Teams desktop app.
In the Teams desktop app, the authentication window should close after sign-in and the Firstup experience should load successfully.
If users still see a blank window, confirm with Firstup Support that:
- The identity provider is sending the SAML response to the new core reply/ACS URL.
- The Firstup configuration has been enabled for the correct community and environment.
- The Audience or Entity ID still uses the vanity URL.
Roll back the change
Coordinate any rollback with Firstup Support.
- If you added the core reply/ACS URL alongside the vanity URL, Firstup can revert its corresponding configuration without requiring you to remove the new URL immediately.
- If you replaced the vanity reply/ACS URL, restore the vanity URL at the same time that Firstup reverts its configuration. Reverting only one side of the configuration may prevent users from signing in.
Comments
0 comments
Article is closed for comments.