The Single Sign-On (SSO) feature of Barco Management Suite (BMS) allows Account administrators to configure and enable/disable single sign-on for one of the claimed domains (e.g. example.com) of the Account.
We support the following SSO protocols:
- OpenID Connect v1.0 (OIDC)
- SAML v2.0
Warning! For security reasons, we require that there is at least one Account administrator that uses the standard Barco ID provider, i.e. not Single Sign-On.
Info! You'll need to be an Account administrator (which is different from an Application administrator).
To become an Account administrator, you will need to either verify your access on your email domain or request access from an existing administrator (how to: see KB10353).
When you don't know the administrator of your Account, please create a support ticket to find this out, see KB6024 for details.
Content
- First time Single Sign-on configuration
- Migrate Users
- Update configuration
- Deactivate configuration (Single Sign-on)
- Remove configuration
- FAQ's
A. First-time configuration
First-time configuration depends on the SSO protocols used. Use the links below to jump to the respective section.
A.1 First time configuration with OpenID Connect v1.0 (OIDC)
Prerequisites: You must have an existing application on your IDP.
To complete the OpenID Connect configuration, you'll need to follow the next 5 steps:
- Start the Single sign-on configuration for the account in BMS
- Configure the application on your IDP
- Complete the Single sign-on configuration in BMS using your IDP Application Secret and Client ID
- Test the Configuration on BMS
- Activate the Single sign-on settings in BMS
- Migrate the users through BMS
These steps are explained in more detail below.
A.1.1. Start the Single sign-on configuration
- Navigate to the Single sign-on settings page on Barco Management Suite.
- Click on Add Configuration
- Enter a name for the configuration and select protocol as OpenID Connect v1.0
- Copy and save the Redirect URI

A.1.2. Configure the application
In this step, we configure the application in your IDP to allow your users access to Barco Single sign-on.
- Use the Redirect URI from BMS in your IDP Application.
- Create and save the Application Secret on your IDP and Application Client ID.
Example: read KB1865 for an example of how to configure this in the Azure portal.
A.1.3. Complete the Single sign-on configuration
- For Discovery URI enter the OpenID configuration endpoint defined by your IDP.
- Optionally, add your scopes to the Scope field, without removing 'openid'.
- Add the Client ID and Secret from your IDP application.
- Optionally, change the Claims when you've specified your own.
- Save this configuration by clicking on Save.
A.1.4 Test the Configuration
Any update or creation of new single sign-on configuration can take up to 30 minutes to propagate across all regions.
- When the specified time has passed after updating or creation of the configuration, go to action menu for the configuration and click on Test.
- You will be prompted to login on your IDP to test the single sign-on
- After successful sign in, the claims returned are shown on this screen.

- If a claim isn’t returned, check the claims mapping match between the IDP and the configuration in BMS.
- After successful completion of the test, proceed to assigning your account’s domain(s) in next step.
A.1.5. Activate the Single sign-on settings
- After you've completed the previous step, the created configuration will show with the Protocol as OpenID Connect v1.0. Currently, status for the domain claimed will be shown as Not Configured.

- To assign the Single sign-on configuration for the domain, click on the Edit assignment menu option.
- A confirmation dialog will pop up and then you may click on Save after reading the impact of this action in the dialog description.

- The domain will be assigned to the configuration and the status for your domain is now Configured.

- A confirmation dialog will pop up and then you may click on Enable after reading the impact of this action in the dialog description.
- The status for your domain is now Enabled.
A.1.6. Migrate the users
See migrate users.
A.2 First-time configuration with SAML v2.0
Prerequisites: You must have an existing application on your IDP.
To complete the SAML configuration, you'll need to follow the next 6 steps:
- Start configuring the application on your IDP
- Start the Single Sign-on configuration on BMS
- Complete configuration on your IDP
- Test the Configuration on BMS
- Activate the Single Sign-on settings
- Migrate the users
These steps are explained in more detail below.
A.2.1 Start configuring the application on your IDP
In this step, we configure the application on your IDP for SAML-based Single Sign-on.
- Select the Single Sign-on mode as SAML.
- Use the SAML endpoints:
Identifier (Entity ID)
https://auth.barco.com/barcociam.onmicrosoft.com/B2C_1A_Common
Reply URL (ACS URL)
https://auth.barco.com/barcociam.onmicrosoft.com/B2C_1A_Common/samlp/sso/assertionconsumer
Index: 0
- Ensure your SAML certificate Signing option is set to sign both Assertion and Response.
- Download the federation metadata file for this application
Example: read KB1865 for an example of how to configure this in the Azure portal.
A.2.2 Start the Single Sign-on configuration on BMS
- Navigate to the Single Sign-on settings page on Barco Management Suite and click on Add Configuration.
- Enter a name for the configuration and Select protocol as SAML v2.0.
- Optionally, change the Assertions for Email, First name or Last name.
Email
assertionSubjectName
This keyword signals Barco to pick the email from the Subject of the SAML Response. Change it only when the Email is not coming in the UPN.
First name
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
Last name
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
- For Your metadata, select the federation metadata file obtained from your IDP & click Upload.

- Set the Signing algorithm under additional settings, according to the configuration on your IDP.

- After the metadata has been uploaded, download the Barco metadata file by clicking the download button.

Note: If the Barco metadata doesn’t start downloading, you may need to check your browser settings.
A.2.3 Complete configuration on your IDP
In this step, you need to use the Barco metadata file obtained from BMS to complete configuring the application on your IDP.
A.2.4 Test the Configuration on BMS
Any update or creation of new single sign-on configuration can take up to 30 minutes to propagate across all regions.
After the configuration in IDP is completed, we will complete the configuration on BMS.
- When the specified time has passed after updating or creation of the configuration, go to action menu for the configuration and click on Test.

- You will be prompted to login on your IDP to test the single sign-on.
- After successful sign in, the claims returned are shown on this screen.

- If a claim isn’t returned, check the claims mapping match between the IDP and the configuration in BMS.
- After successful completion of the test, proceed to assigning your account’s domain(s) in next step.
A.2.5 Activate Single Sign-on settings
- After you've completed the previous step, the created configuration will show with the Protocol as SAML v2.0.
- Currently, status for the domain claimed will be shown as Not Configured.

- Hovering over the Certificate OK green text will show the expiry of the SAML certificates.

- To assign the Single sign-on configuration for the domain, click on the Edit assignment menu option.
- A confirmation dialog will pop up and then you may click on Save after reading the impact of this action in the dialog description.
- The domain will be assigned to the configuration and the status for your domain is now Configured.
- To activate Single sign-on for the domain, click on the Enable Single sign-on menu option.
- A confirmation dialog will pop up and then you may click on Enable after reading the impact of this action in the dialog description.
- The status for your domain is now Enabled.

Once enabled, Single Sign-on may take a short period of time to fully propagate the settings. During this time, no further action is required. When activation is complete:
- All new user sign-ins will be handled through SSO.
- Users who were registered before SSO was enabled, will continue signing in using their existing Barco ID credentials.
- To migrate existing users to SSO, follow the steps described in the next section.
- Once SSO is enabled, users cannot return to password‑based Barco ID login unless the SSO is Disabled or the configuration is Deleted.
A.2.6 Migrate the users
See migrate users.
B. Migrate Users
When you have successfully activated Single sign-on for your domain, you can migrate users from a Barco login to a single sign-on-based login.
- Navigate to User Management → Internal users page.
- For the users with ID Type as Barco ID, click on options → Switch to Single sign-on ID.
Warning! For security reasons, we require that there is at least one Account administrator that uses the standard Barco ID provider, i.e. not Single Sign-On.
C. Update configuration
- General Instructions
- Update Secret for OpenID Connect
- Change Single Sign-on protocol
- Update SAML v2.0 Metadata
C.1 General Instructions
To update the Single sign-on configuration on your domain, follow these next 4 steps:
- Navigate to the Single Sign-on settings page on Barco Management Suite
- From the options menu for the domain, click on Edit.
- Wait for some time until the page is loading, then edit the settings you want to update.
- Click Save.
C.2 Update Secret for OpenID Connect
To update the Secret for your OpenID Connect configuration, follow these next 4 steps:
- After following General instruction steps 1 - 3, scroll to Secret.
- Click on the Edit button.
- Add the updated value.
- Click on the Save (✅) button.


C.3 Change Single Sign-on Configuration
BMS allows to change the Single Sign-on Configuration, even if the domain is Configured or Single sign-on enabled.
However, changing the protocol removes the current configuration which may impact single sign-on users.
To change the Single Sign-on protocol for the domain, you'll need to follow these steps:
- Navigate to the Single Sign-on settings page on Barco Management Suite
- From the options menu for the domain, click on Edit Assignment.
- A modal will appear with the configurations saved for your account, then select the Configuration and you want to use and click on save.
- If single sign-on is enabled for your domain, it’s status will switch to Configured after changing the configuration. Enable it again to activate single sign-on.
C.4 Update SAML v2.0 Metadata
To update the SAML Metadata file for Single sign-on configuration, follow these steps:
- Follow general instructions (steps 1-3).
- Click the folder icon to open File Explorer and select the new metadata file that you want to use.
- After selection, a warning appears on updating metadata. Click Upload.
- Metadata file has been updated successfully.
D. Deactivate Single Sign-on
Deactivating Single Sign-on for a domain does not remove its Single sign-on configuration.
- To deactivate the Single Sign-on configuration for a domain, navigate to the Single Sign-on page on BMS.
- Click on Disable Single sign-on menu option.
- A confirmation dialog will pop up and then you may click on Disable after reading the impact of this action.
- This sets the Status of the domain to Configured.
E. Remove configuration
Removing configuration for an account is only allowed if no domains are assigned to it. To use Single sign-on after the configuration has been removed, go through the steps for First-time configuration to set it up again.
- To remove the Single Sign-on configuration for a domain, navigate to the Single Sign-on page on BMS.
- Click on Delete menu option.
- A confirmation dialog will pop up and then you may click on Delete after reading the impact of this action.
