> ## Documentation Index
> Fetch the complete documentation index at: https://docs.invoca.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Migrating from Legacy SAML SSO to Next-Gen SSO

> How to move your network from Invoca's legacy SAML single sign-on to the new, self-service Next-Gen SSO setup.

## What's changing

Invoca is upgrading its Single Sign-On (SSO) infrastructure. Next-Gen SSO replaces manual configuration with a guided setup wizard for connecting your Identity Provider (IdP). During the migration window, only one SSO connection (Legacy or Next-Gen) is active at a time, and you can freely switch back to Legacy if you run into a problem.

Your users' login experience, your SSO enforcement mode (Disabled/Optional/Mandatory), your default role settings, and your existing user accounts and roles all carry over unchanged.

## Prerequisites

* You must have the **Network Super** role (Invoca's highest-level user role) to access SSO settings.
* You need administrator access to your company's Identity Provider. Supported providers include Okta, Microsoft Entra ID (Azure AD), Google Workspace, ADFS, PingFederate, Auth0, Keycloak, and other SAML 2.0 or OIDC-compatible providers.
* If you already have SAML SSO configured on the legacy system, keep it running until you've fully tested your new Next-Gen SSO connection.
* The Next-Gen SSO setup link expires after **8 hours**. This window covers only the configuration and mapping process — switching your network over to actually use the new connection is a separate step you can complete afterward.

## Step 1: Open SSO settings

Log in to Invoca and go to **Settings > Users**. Click the kebab menu (⋮) near the top right and select **SSO Settings** to confirm your current SSO enforcement mode.

## Step 2: Generate your Next-Gen SSO setup link

1. Locate the **Next-Gen SSO** section in the SSO Settings pane.
2. Enter a friendly name for your connection. This is strictly for your own bookkeeping and isn't related to the implementation.
3. If your Identity Provider is Microsoft Entra ID, select the **EntraID** checkbox. If not, leave it unchecked.
4. Click **Begin SSO Setup**. Invoca generates a time-limited setup link and opens the **Next-Gen SSO Setup Wizard** in a new browser tab.

The setup link is valid for **8 hours** from the moment you click the button. If the wizard session times out, return to the SSO Settings pane and click the button again to generate a new link — any progress you saved is preserved.

## Step 3: Complete the setup wizard

The wizard has five steps:

1. **Create Application** — follow the on-screen instructions to create a new SSO application in your IdP.
2. **Set Up SAML** — the wizard displays a **Single Sign-On URL** (also called ACS URL or Reply URL) and a **Service Provider Entity ID** (also called Audience URI). Copy both values; you'll paste them into your IdP. OIDC connections configure equivalent values differently within the wizard.
3. **Configure Connection** — paste your IdP's metadata URL (recommended) or enter your Sign-In URL, Sign-Out URL, and certificate manually, then click **Create Connection**.
4. **Assign Access** — select which users or groups in your IdP should have SSO access to Invoca.
5. **Test SSO** — run the built-in login test before switching your users over.

## Step 4: Update your Identity Provider

In your IdP's existing Invoca SAML application, update only two values with what you copied in Wizard Step 2: the **Single Sign-On URL / ACS URL** and the **Entity ID / Audience URI**. Leave your existing attribute mappings unchanged — Next-Gen SSO uses the same attribute names Invoca has always used (`first_name`, `last_name`, `email`, and others), and required attribute names are case-sensitive.

## Step 5: Confirm the connection and switch over

Return to the **SSO Settings** pane. Once your connection shows **Ready** (refresh the page, or press **Edit SSO Configuration** and **Enable** if it still shows **Setup Incomplete**), find the **SSO Logins** drop-down and change it from **Legacy** to **Next-Gen**, then click **Save** and confirm.

## Test your connection

Open an incognito or private browser window, go to your Invoca login page, and continue to SSO login. Confirm you're redirected to your IdP, can authenticate, and are returned to Invoca successfully.

## Troubleshooting

* **Certificate mismatch error:** Your IdP's signing certificate doesn't match what Next-Gen SSO has on file, often after a certificate rotation. Re-run the setup wizard and re-enter your IdP's metadata or certificate.
* **Missing attributes error:** A required attribute (like `first_name` or `last_name`) isn't present in your IdP's SSO assertion. Check your IdP's attribute configuration.
* **Setup link expired:** Click **Edit SSO Configuration** in SSO Settings for a new 8-hour link; your progress is saved.
* **Locked out:** Contact Invoca Support immediately. Support can disable SSO enforcement on your network to restore password-based access while you troubleshoot.

Currently logged-in users aren't affected when you switch providers — the change applies only to the next login attempt. You can revert to Legacy SSO at any time during the migration window by changing the SSO Logins setting back; you'll get advance notice before Legacy is retired for good.


## Related topics

- [Legacy SAML SSO Implementation Guide](/s/article/legacy-saml-sso-implementation-guide.md)
- [How to request IdP certificate update](/s/article/request-idp-certificate-update.md)
- [Configure SSO with Okta](/s/article/configure-sso-with-okta.md)
- [SAML SSO: Appendix](/s/article/saml-sso-appendix.md)
- [SAML SSO Setup](/s/article/jhdcp92865-570.md)
