Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.

    English (US)
    MX Spanish (Mexico)
    CA French (Canada)
    US English (US)
    • Home
    • Management Tools
    • Security

    Single Sign On (SSO)

    Written by Conrad Park

    Updated at August 20th, 2026

    Contact Us

    If you still have questions or prefer to get help directly from an agent, please submit a request.
    We’ll get back to you as soon as possible.

    Please fill out the contact form below and we will reply as soon as possible.

    • Getting Started
      Setting up your calendar Managing your alerts Additional Settings
    • Daily Processes
      Candidate Inbox Candidate Profile My Calendar/Calendars Browser Extension My Jobs Approvals Engine Manual and Common Scheduling Practices Form I-9 processes Troubleshooting Forms & Offers
    • Candidate and User Engagement
      Campaigns Conversation Builder Surveys Channels Talent Community Voice Web Management Analytics & Reporting Data Privacy Career Sites
    • Management Tools
      Job Management Scheduling Security Journeys Content Management System (CMS) Multiple Brands Workflows Users, Roles and Permissions Data Feeds Location Management Lookup Tables Assistant Messaging Company Information Client Setup System Attributes Integration Center
    • Contextual AI
      Knowledge Training Library
    • Conversational Events and Campus
      Conversational Events Campus Events
    • Employee Communications
      Communications App Employee Management
    • Release Notes
      2025 2026
    • Workday Feature Descriptions
    + More

    Table of Contents

    Configuration Specification FAQs

    Paradox offers you the ability to access our application with an additional layer of user authorization via their existing user management system and Identity Provider (IdP). This is known as Single Sign On (SSO).


    Configuration

    Paradox strongly recommends the complete configuration and testing of SSO in the staging environment prior to a production implementation.

     

    Setting up SSO requires Paradox support and typically only asynchronous communication methods (e.g. email). The setup process may be conducted as follows:

    1. Expressing interest in the use of SSO to your CS Representative.
    2. Your CS Representative will then configure Paradox as a Service Provider (SP) in your IdP.

    You may then test your new SSO application and confirm the configuration is valid. This same process will need to be repeated in the production environment as well.

    Single Sign On Logic: Basic/Limited Users are not forced to use Single Sign On (SSO) and can log in via MFA if they have login access. There is no validation logic that forces SSO for Basic/Limited Users.

     

    Specification

    Requirement Description
    Name ID format

    We support the following SAML 2.0 values:

    • Unspecified;
    • Email Address; or
    • Transient.
    Username format

    We support the use of either:

    • Email Address; or
    • Employee ID (e.g. UPN).
    SAML 2.0 Attributes

    We require the following attributes:

    • First Name;
    • Last Name; and
    • Email Address or Employee ID (e.g. UPN).

    FAQs

    What is Paradox's SP Metadata? Provided during the implementation process.
    What is Paradox's Application Entity ID? Provided during the implementation process.
    What is Paradox's Assertion Consumer Service (ACS) URL? Provided during the implementation process.
    What is Paradox's Single Logout (SLO) URL? Provided during the implementation process.
    What Signature Algorithm does Paradox use? SHA-256
    What Digest Algorithm does Paradox use? SHA-256
    Does Paradox support both IdP and SP initiated SSO? Yes
    Are response assertion signatures required? Yes
    Is assertion encryption required? No
    Does Paradox support assertion encryption? Yes
    Is SSO Multi-Factor Authentication (MFA) required? No
    Does Paradox support SSO MFA? Yes
    Is the ForceAuthn parameter required? No
    Is the RelayState parameter required? No
    I logged out of the system. Why does it still show me as logged in? When a user logs out of the CEM, the session is only ended locally, meaning that the session specific to the Paradox app is terminated and all related local data is cleared. Paradox does not intentionally trigger a Single Logout (SLO) request to the Identity Provider (IdP), as doing so would log the user out of all other applications that rely on the same IdP. This could disrupt their ongoing work in those apps, so the logout experience is limited to just the Paradox service.
    sso mfa multi-factor authentication 2factor 2-factor

    Was this article helpful?

    Yes
    No
    Give feedback about this article

    Related Articles

    • Employee Attributes
    • Event Attributes
    • Monthly Conversations (Employee) Report
    • Paradox public IP addresses

    Copyright 2026 – Paradox.

    Knowledge Base Software powered by Helpjuice

    Expand