SAML SSO Restrictions for Web Store in NetSuite
Understand SAML SSO restrictions for web stores, including custom domain requirements and authentication methods.
Starting with the SAML SSO implementation in NetSuite, several restrictions apply specifically to the Service Provider (SP)-initiated flow for web stores. These restrictions are crucial for ensuring that your web store functions correctly while maintaining authentication security.
What Are the SAML SSO Restrictions for Web Stores?
The following restrictions apply to the SAML SSO service provider-initiated flow:
- Custom Domain Requirement: The SP-initiated flow is supported only for sites on custom domains; it does not work with netsuite.com domains.
- Exclusive Authentication Method: You cannot utilize both SAML and OpenID Connect (OIDC) Single Sign-on for the same website. You must select one method.
- Mandatory Website Protection: To use the SP-initiated flow, your website must be fully protected, which requires the following steps:
- On the Set Up Web Site form, navigate to the Web Presence subtab. In the Web Site section, ensure that the Advanced Site Customization box is checked.
- Access the record at Commerce > Websites > Website List and edit the web store record. On the Shopping subtab, within the Registration Page section, check the Password-Protect Entire Site box.
Additional Information on SAML SSO
It's important to note that SAML does not have to be the primary authentication method for web stores. If you want users to be redirected to an external Identity Provider (IdP) login page, remember to check the Primary Authentication Method box.
For more detailed interactions with NetSuite using SAML, you can refer to additional resources in the NetSuite documentation about SAML SSO integrations. Understanding these restrictions is essential for developers and administrators to implement secure and efficient single sign-on solutions for web stores across various industries.
Key Considerations
- Always confirm you are using a custom domain for SAML SSO.
- Decide on an authentication method early in your web store setup.
- Protect your entire site to leverage the SP-initiated flow effectively.
Key Takeaways
- The SP-initiated flow for SAML SSO is exclusive to custom domains.
- SAML and OIDC cannot be used simultaneously for the same website.
- Full website protection is mandatory for utilizing these SSO features.
Frequently Asked Questions (4)
Does the SAML SSO SP-initiated flow work with netsuite.com domains?
Can SAML and OpenID Connect (OIDC) be used simultaneously for a NetSuite web store?
What steps are necessary to protect a website for SP-initiated SAML SSO flow in NetSuite?
Is the SAML SSO SP-initiated flow mandatory as the primary authentication method?
Was this article helpful?
More in Commerce
- SuiteCommerce CAPTCHA Configuration Options and Setup
Configure SuiteCommerce CAPTCHA for enhanced security. Enable CAPTCHA for registration, login, guest checkout, and orders.
- Single Sign-On Integration for NetSuite Web Stores
Implement inbound single sign-on integration for NetSuite web stores using SAML or OpenID Connect for seamless access.
- Facets Management for Commerce in NetSuite
Facets management in NetSuite Commerce optimizes item search filters, enhancing performance and improving user experience.
- SuiteCommerce Analytics Data and Cookie Consent Integration
SuiteCommerce Analytics Data enables tracking of shopper behavior. This requires a cookie consent extension for user preferences.
Advertising
Reach Commerce Professionals
Put your product in front of NetSuite experts who work with Commerce every day.
Sponsor This Category