<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Webex Control Hub - SSO in Webex Administration</title>
    <link>https://community.cisco.com/t5/webex-administration/webex-control-hub-sso/m-p/5375770#M5726</link>
    <description>&lt;OL&gt;
&lt;LI&gt;Yes with &lt;A href="https://help.webex.com/en-us/article/ngp4sr8/SSO-with-multiple-IdPs-in-Webex#generic-template_7359cc82-9b8c-4d30-8836-73aa07a55858" target="_blank" rel="noopener"&gt;IdP routing rules&lt;/A&gt;. You can have an ordered list of match logic based on email domain of the user account or group membership with a last resort option without a match criteria. Be advised that some InfoSec folks feel that the ability to bypass SSO is a risk, so be sure you get the relevant approvals internally before configuring this.&lt;/LI&gt;
&lt;LI&gt;First, I wanted to warn "don't do this!" Users and endpoints absolutely belong in the same tenant; some features only work intra-tenant. To answer the question directly though: only one Webex tenant could use the &lt;A href="https://help.webex.com/en-us/article/heauzeb/Set-up-the-Entra-ID-Wizard-App-in-Control-Hub" target="_blank" rel="noopener"&gt;Entra ID Wizard App integration&lt;/A&gt; (i.e. the easy button.). The other would need to use SAML/OIDC, and optionally SCIM 2.0 for account synchronization, the hard way from Entra as an enterprise application.&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Tue, 10 Mar 2026 18:38:45 GMT</pubDate>
    <dc:creator>Jonathan Schulenberg</dc:creator>
    <dc:date>2026-03-10T18:38:45Z</dc:date>
    <item>
      <title>Webex Control Hub - SSO</title>
      <link>https://community.cisco.com/t5/webex-administration/webex-control-hub-sso/m-p/5375649#M5724</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have a few queries regarding SSO on WebEx control hub and was hoping someone may be able to answer the below:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Is it possible to enable SSO on WebEx control hub, whilst allowing some users to sign in using their WebEx credentials rather than SSO?&lt;/LI&gt;&lt;LI&gt;Is it possible to have 2 WebEx tenants configured to the same SSO provider. Example User WebEx tenant and Device WebEx tenant both using a single Microsoft tenant for SSO.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2026 10:07:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/webex-administration/webex-control-hub-sso/m-p/5375649#M5724</guid>
      <dc:creator>RobT1923</dc:creator>
      <dc:date>2026-03-10T10:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: Webex Control Hub - SSO</title>
      <link>https://community.cisco.com/t5/webex-administration/webex-control-hub-sso/m-p/5375770#M5726</link>
      <description>&lt;OL&gt;
&lt;LI&gt;Yes with &lt;A href="https://help.webex.com/en-us/article/ngp4sr8/SSO-with-multiple-IdPs-in-Webex#generic-template_7359cc82-9b8c-4d30-8836-73aa07a55858" target="_blank" rel="noopener"&gt;IdP routing rules&lt;/A&gt;. You can have an ordered list of match logic based on email domain of the user account or group membership with a last resort option without a match criteria. Be advised that some InfoSec folks feel that the ability to bypass SSO is a risk, so be sure you get the relevant approvals internally before configuring this.&lt;/LI&gt;
&lt;LI&gt;First, I wanted to warn "don't do this!" Users and endpoints absolutely belong in the same tenant; some features only work intra-tenant. To answer the question directly though: only one Webex tenant could use the &lt;A href="https://help.webex.com/en-us/article/heauzeb/Set-up-the-Entra-ID-Wizard-App-in-Control-Hub" target="_blank" rel="noopener"&gt;Entra ID Wizard App integration&lt;/A&gt; (i.e. the easy button.). The other would need to use SAML/OIDC, and optionally SCIM 2.0 for account synchronization, the hard way from Entra as an enterprise application.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Tue, 10 Mar 2026 18:38:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/webex-administration/webex-control-hub-sso/m-p/5375770#M5726</guid>
      <dc:creator>Jonathan Schulenberg</dc:creator>
      <dc:date>2026-03-10T18:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: Webex Control Hub - SSO</title>
      <link>https://community.cisco.com/t5/webex-administration/webex-control-hub-sso/m-p/5375924#M5727</link>
      <description>&lt;P&gt;Thanks, would you be able to say which features only work intra-tenant?&lt;BR /&gt;The devices are going to be in Teams mode or Room OS utilising OBTJ.&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2026 13:00:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/webex-administration/webex-control-hub-sso/m-p/5375924#M5727</guid>
      <dc:creator>RobT1923</dc:creator>
      <dc:date>2026-03-11T13:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: Webex Control Hub - SSO</title>
      <link>https://community.cisco.com/t5/webex-administration/webex-control-hub-sso/m-p/5376989#M5732</link>
      <description>&lt;P&gt;I'm reluctant to even answer this question because it's such a bad idea. It will make everything more difficult, even sourcing. This is not how Control Hub was designed to function. Why do you want to separate them so badly?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2026 21:37:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/webex-administration/webex-control-hub-sso/m-p/5376989#M5732</guid>
      <dc:creator>Jonathan Schulenberg</dc:creator>
      <dc:date>2026-03-16T21:37:57Z</dc:date>
    </item>
    <item>
      <title>Re: Webex Control Hub - SSO</title>
      <link>https://community.cisco.com/t5/webex-administration/webex-control-hub-sso/m-p/5377082#M5733</link>
      <description>&lt;P&gt;I don't want to separate them, i want them on the same tenant but management has asked for them to be separate and i can only see it causing issues.&lt;BR /&gt;&lt;BR /&gt;One of the reasons for separating was due to the fact that its a tenant shared by multiple regions, and they didn't want other regions managing devices. I've been able to confirm that location admin is the way to go for this so that helps my argument for staying on one tenant.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2026 09:43:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/webex-administration/webex-control-hub-sso/m-p/5377082#M5733</guid>
      <dc:creator>RobT1923</dc:creator>
      <dc:date>2026-03-17T09:43:52Z</dc:date>
    </item>
  </channel>
</rss>

