Federated SSO requirements
Review the supported protocols, infrastructure expectations, and implementation timelines required to set up Federated Single Sign-On (SSO) with Thomson Reuters Account.
Supported technologies
Thomson Reuters Account supports both the SAML 2.0 and OIDC protocols for Federated Single Sign-On (SSO).
Unsupported technologies
Thomson Reuters Account doesn’t support any other Federated SSO protocol, including any non-standard custom protocol.
Federated SSO support
Thomson Reuters doesn’t provide code or end-user support for your Workforce Identity service. Your firm's IT department needs to manage your firm's Workforce Identity service and if needed, work with your vendor for development, management, configuration, or end-user support.
Implementation duration
The duration of a Federated SSO implementation depends mostly on your IT department's familiarity with the process and any testing and transition requirements you have.
If you have an existing Workforce Identity service in place and you are already federating with 1 or more external partners, implementations can often be completed and tested in under a week.
If you have the necessary Workforce Identity service in place but you have never used the Federated SSO feature, plan for a longer implementation as you acquire the necessary in-house knowledge to use your system for Federated SSO. The vendor of your Workforce Identity service can assist you with this.
If you don’t have an existing Workforce Identity service and have no prior knowledge of the process, several months are likely required to implement a solution.
Summary of supported federated SSO standards
Thomson Reuters Account supports the following Federated SSO standards:
SAML
- SAML 2.0 protocol with the Browser/POST profile.
- Our preferred method is to receive a SAML IDP metadata URL, but exchange of SAML metadata XML files for defining the SAML connection is also supported.
- For digital signatures, the Thomson Reuters Account supports signing of either the entire SAML Response or the SAML Assertion inside the Response only.
- Thomson Reuters Account supports XML Encryption of either the entire SAML Assertion or the SAML NameIdentifier only. This is turned on by request, as our service already uses a TLS-encrypted connection, ensuring the entire communication is encrypted by default.
- Thomson Reuters Account supports the use of self-issued X.509 certificates for both digital signatures and encryption.
- SP-Initiated SSO transfers.
- Signed authentication requests are supported and can be turned on upon customer request.
- SCIM for user provisioning is not currently supported.
OpenID Connect (OIDC)
OIDC is supported but not preferred. Contact us for more details if this is a requirement.