This topic describes how to configure OneLogin to provide SSO for Blue Jeans using SAML.
Log into OneLogin as an admin and go to Apps > Add Apps.
Search for and select the Blue Jeans Network connector.
The initial Configuration tab appears.
Ensure that in the Connectors section, the SAML2.0 connector is selected.
Click Save to add the app to your Company Apps and display additional configuration tabs.
The Info tab appears.
Go to the Parameters tab and map Blue Jeans attributes to OneLogin attributes.
In most cases, you should accept the default values. Ensure that the Blue Jeans Network field Username is set to AD user name if you use Active Directory as the third party directory. Otherwise, set Username to Email. Click Save if you made any changes on the Parameters tab.
You can also go to Users > All Users to add the app to individual user accounts.
Go to the SSO tab to view the values that you'll copy into your Blue Jeans instance to set up SAML SSO.
Open a new browser tab and go to the Blue Jeans login page and login as admin to enter OneLogin's SAML SSO values.
Go to Admin > Group Settings > Security to see the SAML configuration page.
Select the SAML Single Sign On option.
Check the Enable automatic provisioning option if you want to use Just In Time Provisioning.
Copy the value in the RelayState field, which you will insert into OneLogin to guide the authentication request redirects.
Select the Pick User ID from <saml2:nameID> element option.
Enter the following values into the Configure SAML Attribute Mapping fields. When mapping SAML attributes, cases and spacing matter so be sure to input this information exactly as shown.
Field Name Value
Go back to the OneLogin SSO tab and copy the SAML values from the OneLogin SSO tab to the analogous Blue Jeans fields.
Copy this OneLogin SSO field value: To this Blue Jeans SSO settings field:
SAML 2.0 Endpoint (HTTP)
Password Change URL
To get the X.509 Certificate, click View Details to open the certificate page. Select X.509 PEM from the drop-down list and then click Download.
Click the Choose File button and navigate to your downloaded X.509 PEM Certificate. Select the certificate and click Open.
When you have completed the Blue Jeans Security tab, it should appear as follows.
Go to the OneLogin Configuration tab and paste the RelayState that you copied in step 8.
This value tells OneLogin where to send the SAML message.
Test the SAML connection.
Ensure that you have a user account in both OneLogin and Blue Jeans that use the same email as the username.
You can create a test user, or you can use your own account if you choose.
Make sure that you are logged out of Blue Jeans.
Log in to OneLogin as an admin and give the test user (or yourself) access to the Blue Jeans app in OneLogin. (See step 6 above)
Log in to OneLogin as the test user.
Click the Blue Jeans icon on the OneLogin dashboard.
If the test user is able to access Blue Jeans, then SAML works.