Single tenant SSO
The Snow License Manager product supports industry-standard SAML 2.0 for integration with SAML Identity Providers (“IDP”).Snow License Manager supports a single SAML configuration for authenticating users via an IDP when trying to access the service.
For Enterprise Edition installations of Snow License Manager (SLM), there is only a single logical tenant (although this tenant may comprise of multiple legal entities, company fractions, subsidiaries, business units, etc.).
When implementing Single Sign On (SSO) / Multi Factor Authentication (MFA) in this scenario (typically for a single customer-hosted instance of SLM), the SAML configuration in SLM is used to bind the Snow License Manager website (SP) to the customers own SSO solutions (IDP), such as AzureAD, OneLogin, Okta, etc. for authenticating their users.
Multitenant SSO
In a multitenant scenario, multiple customers want to access the same Snow License Manager Website, but are only given access to their assigned tenant within the solution. In order to implement SSO when each customer has their own IDP solution for their users, this requires the addition of a central IDP instance to act as a gateway for the others, since SLM only supports a single SAML configuration towards the IDP.(Note: The Identity Providers may use different terms for this capability: OneLogin=”Trusted IDPs”, Okta=”Integrating Enterprise Identities”, etc.)
In this scenario, multiple end-customers authenticate against the same Snow License Manager Website, but need to end up in separate tenants. Each customer may have their own IDP solution, and 2FA/MFA requirements.
In order to achieve this, an IDP solution is placed in front of the Snow Licence Manager website.
All the other customer IDP solutions are integrated into this central IDP solution, which in turn is integrated into Snow License Manager using the built-in SAML support.
New Capabilities
For SPE customers:- Each customer can use their own IDP solution for authentication to SLM (SPE), to achieve MFA/SSO across all the tools and systems their employees need to access.
- Each customer can effectively terminate access to SLM (SPE) completely on their own, based on their own AD/AzureAD groups, and according to their internal joiners/leavers process.
For SPE partners:
- Many prospects and existing customers demand MFA/SSO support. This requirement can now be satisfied.
- Offering SSO/MFA is an enhanced service level for the customer.
- The central IDP solutions also support the current process of manually creating user accounts, for end customers who don’t want to implement SSO only for a handful SLM users.
Requirements:
- Snow License Manager, configured with SAML towards the Identity Provider.
- A SAML Identity Provider capable of integrating multiple additional IDPs.
(Note: The Identity Providers may use different terms for this capability: OneLogin=”Trusted IDPs”, Okta=”Integrating Enterprise Identities”, etc.)
Additional Resources:
Configure Snow Licence Manager - Enable Federated authentication
- This document here describes how to configure SAML in Snow License Manager, including common examples.
Terminology
SSO = Single Sign On
This commonly means you use the same identity to authenticate across all systems, even though you typically have to sign in with this identity more than one time.
MFA = Multi-factor Authentication.
In addition to logging in with your username/password, you are asked to provide additional verification data, such as via a code generator app linked to your trusted device, a passcode via SMS to your registered phone number, verification link to your email, and similar.
2FA = 2 Factor Authentication.
The same as above, but only 1 additional method beyond your username/password. “2FA” and “MFA” are both typically understood to mean the same thing: - taking additional steps to verify your identity.
SAML = Security Assertion Markup Language.
An open standard that allows identity providers (IdP) to pass authorization credentials to service providers (SP). In a SAML context, Snow License Manager is acting as a SAML Service Provider (SP).
SP = SAML Service Provider.
The service providing the resource users want to access. (e.g. Snow License Manager).
IDP = SAML Identity Provider.
The directory solution managing the identification and authentication of users. (E.g. AzureAD, OneLogin, Okta, etc.)
Authentication = The act of identifying who a user is, and whether that user is who they claim to be from a security context.
Consider this equivalent to a security checkpoint at the airport, where you show your boarding pass and identification to be allowed into the departure area.
In Snow License Manager, this is controlled by a user record created in SMACC, which the IDP matches with its authenticated user identity, typically by Email address. When SAML is activated, SLM forwards any logon attempts to the IDP to verify the authenticity of the user.
Authorization = What you are allowed to do in the system.
Think of this as the act of controlling what flights you are allowed to board, and whether you are allowed entry to business class or economy class on the plane.
In Snow License Manager, this is controlled by Roles in SMACC, which control what the authenticated users are allowed to view and perform in the system.
Was this helpful?
Related Articles
Best practices for large environments (Snow License Manager and Snow Inventory) 1.14KNumber of Views Reset two-factor authentication for Flexera SVR 7Number of Views Okta “400 Login Failed” error during single sign-on (SSO) 46Number of Views Snow License Manager: How to look for duplicates 214Number of Views Single sign-on in Snow Atlas 27Number of Views
Revenera Assistant
Online
Hi, I am Reva - Ask me anything.
Updates
No new updates
Chat
Home
Updates
/**/
Thanks for the feedback!
Your feedback has been saved.Rate this response:
1
2
3
4
5
Add Additional feedback ( Optional )
0/240
English
English
Language changed successfully
Something went wrong
Email sent successfully
Something went wrong
Case create successfully
Are you sure you want to cancel
the case creation?
Please select a product to submit the case.
Please select a product version to submit the case.
0/255
Upload Attachment
File Upload
Maximum file
size allowed is 3 MB.
File type
not supported.
Supported file types:
Documents (.txt, .doc, .docx, .pdf), Images (.jpg, .png), Comma Separated Files
(.csv) Speadsheets (.xlsx, .xls)
Are you sure you want to cancel the case creation?
Case closed successfully
File Upload
Maximum file size allowed is 3 MB.
File type not supported.
Supported file types:
Documents (.txt, .doc, .docx, .pdf), Images (.jpg, .png), Comma Separated Files
(.csv) Speadsheets (.xlsx, .xls)
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
File Upload
Maximum file
size allowed is 3 MB.
File type
not supported.
Supported file types:
Documents (.txt, .doc, .docx, .pdf), Images (.jpg, .png), Comma Separated Files
(.csv) Speadsheets (.xlsx, .xls)
Revenera Assistant
© 2026 Flexera Software. All Rights Reserved.
Case id: 00001065
Activity: Status change: 2 hours ago