How to Configure SAML SSO With OneLogin
Overview
OneLogin can act as an Identity Provider (IdP) for the Cisco Meraki Dashboard, enabling users to sign in through SAML single sign-on (SSO). This article provides an example walk-through of the configuration on both the OneLogin and Dashboard sides.
Before proceeding, refer to the article on SAML integration for Dashboard.
Prerequisites
- A OneLogin account with a user that has permissions to create company apps.
- Access to the Cisco Meraki Dashboard with permissions to configure Organization > Settings > SAML Configuration and Organization > Administrators > SAML administrator roles.
Step-by-step instructions
Add and configure the Meraki app in OneLogin
-
Sign in to OneLogin as a user with permissions to create company apps.
-
From the home page, select APPS > Add Apps.

-
Search for meraki and select the Meraki app.

-
On the initial configuration page:
-
Under Personal or Organization App, choose the bubble for the organization.

-
Under Connectors, choose the bubble for SAML2.0.

-
Select Save.
Configure the SAML consumer URL and certificate
-
On the Configuration tab, enter the SAML Consumer URL. This is the Consumer URL from Organization > Settings > SAML Configuration in Dashboard.

-
On the SSO tab, select View Details under the X.509 Certificate.

-
Copy the SHA1-Fingerprint and enter it in the X.509 cert SHA1 fingerprint field under Organization > Settings > SAML Configuration in Dashboard.

-
Return to the previous page by selecting the Meraki (or custom name entered earlier) app under Apps using this certificate. Then select the SSO tab.
(Optional) Enable Single Logout
Enable Single Logout (SLO) by copying the SLO Endpoint (HTTP) field and pasting it into the SLO logout URL field under Organization > Settings > SAML Configuration in Dashboard.
If enabled, logging out in Dashboard logs the user out of OneLogin and any compatible apps as well.

Set access roles
-
On the Access tab, ensure that any desired Roles are selected. If none are selected, manually give users access to the app.
-
Select Save.

Grant user access and assign a role
-
On the Users tab, select a user to grant access. In this example, the user 'SAML Demo' is part of the 'Default' role.

-
Enter a Role for the user. This must match a Role configured under Organization > Administrators > SAML administrator roles in Dashboard.

-
Select Save.

Verification
The configured user can seamlessly sign in to Dashboard by selecting the Meraki app.
Troubleshooting
If an error appears, confirm that all necessary fields are correctly populated and that both the user's Role and the SHA1 fingerprint match correctly between OneLogin and Dashboard.
For information on resolving possible error messages, refer to the article on SAML Login History Error Messages.
Additional resources
- For any questions on OneLogin, refer to the OneLogin documentation.
- For more information on Dashboard permissions and administrator types, refer to the article on managing administrative users.

