Search
Search Account management Support Help and Support.

Federated SSO common questions

Find answers to common questions about configuring and managing Federated SSO connections with Thomson Reuters Account.
If you have any immediate questions, review the following list:
  • Does Thomson Reuters provide staging versions of products for testing Federated SSO connections?
    • Typically, no, while in some cases this may be possible. Discuss with the Thomson Reuters SSO team if you require this. Normally you can create a staging and a production connection on your side and both will target the same production version of the Thomson Reuters product. They are treated as 2 completely independent connections. Note when using 2 connections you must choose separate Issuer URNs since we need to be able to differentiate them, and different email domains would typically need to be used for your users.
  • What are the protocol elements to be used for the customer's Federated SSO configuration?
    • We’ll provide an SP metadata XML file that will include all the required information, so normally this XML file can be imported into your system to set up the connection. However, for reference, here are 2 key values you may need:
      • SAML Entity ID:
        trtasso.thomson.com
      • SAML v2.0 Endpoint:
        https://trtasso.thomson.com/sp/ACS.saml2
  • Federated SSO protocol isn't listed, or I want to create a custom protocol. Can I?
    • No. Thomson Reuters Account supports only the protocols listed in this article.
  • What should I set the Name Identifier to in the SSO token?
    • Anything you like, subject to the restriction that it 's normal text characters no longer than 250 characters in length. We don’t parse or interpret the value in any way. We’ll store this value in the Thomson Reuters Account user profile to create an account link. We strongly recommend a value that will never change for a user. Employee IDs, GUIDs, or SIDs make good values that meet this recommendation, while email addresses typically don’t since they may change over time.
  • Do I need to change the firewall to support SAML Browser/POST? Does the Workforce Identity service URL need to be publicly visible?
    • No, this SAML profile works by client browser redirects. Your internal Workforce Identity service URL need only be visible to your users, not externally by Thomson Reuters Account.
  • Why am I being asked to provide contact information?
    • If we determine that your Workforce Identity service appears to not be available or is passing us invalid information, we want someone in your organization we can contact to investigate and help resolve the problem. We would only do this if we are certain the problem lies on your side of the Federated SSO connection. We may also contact you if any of your X.509 certificates are expiring soon. If possible, provide a group distribution list instead of an individual email address so that we won't lose contact with you if an individual leaves your firm.
  • Is there a way to exclude certain users from Federated SSO?
    • While not generally recommended, some Thomson Reuters products may provide this option.