Single Sign-On is available for Enterprise subscription holders only. See our pricing page for more information.
Self-service setup of RealVNC Account SSO is now supported through the RealVNC Portal. Go to People > Single-Sign-On to find the setup instructions.
Supported identity providers
While the SSO setup is enabled to be generic to any OIDC provider, only Okta and Entra ID have been fully tested by RealVNC so we cannot ensure that every OIDC provider will work for RealVNC Account SSO. If you experience any issues, please contact our Support Team.
Restrictions and Security Considerations
When enabling RealVNC Account SSO for your RealVNC Connect Team, please be aware of the below restrictions and security considerations.
Restrictions
Teams
- Your SSO tenant/identity provider can only be associated with one Team.
- All other members of an SSO-enabled Team must be SSO users; users with a standard RealVNC account cannot be part of an SSO-enabled Team.
-
Mandated two-factor authentication using RealVNC Connect's 2FA cannot be enabled on SSO-enabled Teams.
- Note, this does not prevent using your identity provider's 2FA for accounts, this refers to RealVNC's own 2FA for accounts which cannot be used with an SSO account.
- Once a Team has SSO enabled, it cannot be undone.
People (Users)
- SSO Users cannot sign in to the License Wizard, a cloud connectivity token must be used instead.
- SSO Users cannot change their contact details or authentication settings in the RealVNC Connect Portal as they are controlled by your identity provider.
Compatibility
- Role-linked SSO is currently not compatible with our new My Organization feature.
Security considerations
Once your Team has been enabled for SSO sign-in, please be aware that:
- RealVNC Connect will not perform device authorization or two-factor authentication for users
-
Mandated two-factor authentication using RealVNC Connect's 2FA is disabled on the Team.
- Note, this does not prevent using your identity provider's 2FA for accounts, this refers to RealVNC's own 2FA for accounts which cannot be used with an SSO account.
- It is up to the customer to ensure that their identity provider is configured to provide adequate security for their users.
Before you begin
To configure SSO you will need the following details from your OIDC identity provider:
- Your SSO provider type - Entra, Okta, or Generic for any other OIDC-compatible provider
- An OIDC Identifier (URL slug) - a unique string used to distinguish this configuration for SSO sign-in
- Your Company name
- The Identity URI - the Issuer URI from your identity provider. This unique URL identifies the OIDC issuer and is used for token validation. You can find it in your provider's settings. Entra ID only: Please ensure you append /v2.0 to the end of your Issuer URL
- The Client ID - a unique value that identifies your identity provider, also found in your provider's settings. Not required for Entra ID.
Please ensure you have all of this information prepared before starting. The configuration form will not save if it is not completed in one go.
Step 1: Configure your SSO
In the RealVNC Portal, go to People > Single-Sign-On and select the Configuration tab.
- Under Step 1, click Start configuration.
- In Select your SSO provider, choose Entra, Okta, or Generic. We support Entra ID and Okta with detailed setup guides; if you're using a different provider that supports OIDC, choose Generic.
- Enter your OIDC Identifier (URL slug), Company name, Identity URI, and Client ID (Client ID is not required for Entra ID).
- Under Just in Time User Provisioning, choose a provisioning method (see Just in Time User Provisioning Options below).
- Click Confirm details.
- Review the SSO summary of changes screen. Use Back to make corrections, then click Submit.
Just in Time User Provisioning Options
As part of the SSO setup process, you will need to select a provisioning method for the users in your RealVNC Connect Team. This will determine how users are added to your Team when signing in using SSO.
Auto Provisioning
This option allows users from your OIDC provider to sign in and be automatically added to your remote access team with the User role.
Role-linked auto provisioning
This option allows users from your OIDC provider to sign in and be automatically added to your remote access team, with their roles mapped from those defined in your OIDC provider.
No provisioning
This option allows users from your OIDC provider to sign in, but they won't be automatically added to your remote access team. Their accounts must be created and managed through the SSO User Management page found in the RealVNC Portal.
Step 2: Add and verify your domain
To activate and ensure your SSO setup is secure, we need to verify your domain. You must complete your SSO configuration (Step 1) before adding and validating your domain.
- On the Configuration tab, under Step 2, click Add domain.
- Enter your domain and click Continue.
- A unique TXT record is generated to verify your ownership of the domain. Click Copy, then click Done.
- Add the TXT record to your domain in your DNS provider.
- Back on the Configuration tab, click Verify domain next to your domain. Verification is typically instant but can take between 24-72 hours to complete depending on your DNS provider.
If verification fails, you will see the message "Domain verification failed, please check you have entered the correct TXT record in your DNS provider and run the verification again" and the domain will show as UNVERIFIED. Check that the TXT record has been added to the correct domain in your DNS provider exactly as generated, allow time for DNS changes to propagate, then click Verify domain again.
Step 3: Enable SSO
Once you have completed the configuration and domain verification above, you can activate SSO for your account and users. On the Configuration tab, under Step 3, click Enable SSO. The button remains unavailable until Steps 1 and 2 are complete.
Please remember that once a Team has SSO enabled, it cannot be undone.
After enabling SSO you may need to manually create or migrate users. You can do this in the SSO User Management tab - see the next section.
Step 4: Managing SSO users
RealVNC Connect accounts must have a unique email address/UPN, which means when you want to enable RealVNC Account SSO for an existing team we will need to migrate your users from using standard RealVNC Accounts to SSO-enabled RealVNC accounts.
User management and migration can be carried out via the RealVNC Portal. Navigate to People > Single-Sign-On and select the SSO User Management tab.
From here you can use the provided template to migrate existing RealVNC users to SSO-enabled accounts.
If you have enabled auto or role-linked provisioning, you will not be able to create new users here as these will be automatically created when your users attempt to log in to RealVNC via SSO for the first time.
The downloadable template on this page works for both new user creation and user migration, so no formatting changes are needed - just fill it in and upload.
Existing user migration
To migrate existing users you will need to provide their existing RealVNC Username (email address), their SSO username (email address) and their SSO ID. You will find the SSO related details in your OIDC provider.
To migrate existing users you will need to provide their existing RealVNC Username (email address), their SSO username (email address) and their SSO ID.
To note, you will find the SSO related details in your OIDC provider and roles could be one of User, Device Joiner, Technician, Manager or Admin.
New user creation
To create new users you will need to provide their SSO username (email address), SSO ID and their role.
You cannot invite new users if you selected auto or role-linked auto provisioning.
For teams using the My Organization feature
To create new users you will need to provide their SSO username (email address), SSO ID, their role and whether to give each user access to all the devices in your hierarchy.
To migrate existing users you will also need to provide their existing RealVNC Username (email address).
To note, you will find the SSO related details in your OIDC provider and roles could be one of User, Device Joiner, Technician, Manager or Admin.
Uploading your CSV file
- Click Download CSV template and complete a row for each user, as described above for your team type.
- Click Upload CSV.
- Drag and drop your completed CSV file into the upload area, or click Choose file to browse for it, then click Continue.
SSO Role-Linking
Before migrating users to SSO accounts, ensure each user has an assigned role in the SSO Admin Console. Users without assigned roles will not be included in the team until their roles are configured.
Validating uploaded users
After uploading, the User validation screen shows which users passed or failed validation, with a row reference and error description for each failure (for example, SSO username: Required). To fix failures:
- Use the Status filter to show Failed users.
- Click Export users to export the list as a CSV file.
- Correct the errors in the exported file, then upload it again.
Getting help
For help finding the correct information for your IDP, see our individual Help Center pages for Entra ID & Okta. For other SSO providers, or if you experience any issues, please contact our Support team.
Comments
Article is closed for comments.