<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.appian.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>KB-2343 Transferring SAML after domain change</title><link>https://community.appian.com/support/w/kb/3548/kb-2343-transferring-saml-after-domain-change</link><description /><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>KB-2343 Transferring SAML after domain change</title><link>https://community.appian.com/support/w/kb/3548/kb-2343-transferring-saml-after-domain-change</link><pubDate>Tue, 01 Jul 2025 16:10:45 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:5c48dff1-a413-460d-9ab6-c5b7ec54e999</guid><dc:creator>pauline.delacruz</dc:creator><comments>https://community.appian.com/support/w/kb/3548/kb-2343-transferring-saml-after-domain-change#comments</comments><description>Current Revision posted to Appian Knowledge Base by pauline.delacruz on 7/1/2025 4:10:45 PM&lt;br /&gt;
&lt;h2 id="mcetoc_1iv3boj6e0"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;SAML is tied to the Service Provider Hostname, hence when changing to a&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/latest/Using_a_Custom_Domain_in_Appian_Cloud.html"&gt;custom domain&lt;/a&gt; there will be required changes to reconfigure aspects of SAML.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;The required steps may vary with the Identify Provider (IDP) or custom configurations, and this KB article is intended to be a guide to assist with the common changes. For further assistance please consult your IDP provider, and reach out to Appian Support through a support case.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Table of Contents:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#appian-saml"&gt;For Appian SAML configurations&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#sp-metadata"&gt;SP Metadata&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#idp"&gt;IDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#saving-changes"&gt;Saving Changes to SAML Configuration in Appian&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#user-start-pages"&gt;User Start Pages&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#recommended"&gt;Recommended&amp;nbsp;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;&lt;a id="appian-saml"&gt;&lt;/a&gt;For Appian SAML configurations&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;The hostname is referenced in:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Service Provider (SP) Metadata&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;The hostname may also be referenced in:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Identity Provider (IDP) Metadata&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Service Provider PEM file Signing Certificate&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;User Start Pages&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;&lt;a id="sp-metadata"&gt;&lt;/a&gt;SP Metadata&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;To regenerate the SP Metadata with the new customer domain:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;By Preference:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Review the Entity ID, and Service Provider Signing Certificate, and change as preferred. These will typically reference the Appian Hostname.&lt;/span&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;The Entity ID does not have to reflect the Hostname, as the Entity ID is a text value. It is important that this value aligns between SP and IDP.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;The Signing Certificate may reflect the hostname in the Common Name.&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Required:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Even if there are no manual changes to the SP Settings, you will still regenerate the SP Metadata to point to the new domain, this is because the location attributes for the SAML assertion reference the hostname.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Once the SP settings are updated, regenerate the SP Metadata, this will download a XML file with the required connection information.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Review the XML metadata file to ensure the old domain is replaced with the new domain, and upload this SP metadata to you IDP.&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Please see the following resource for more information on&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/latest/SAML_for_Single_Sign-On.html#service-provider-metadata"&gt;service provider metadata&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Additionally, please see the following for more &lt;a href="/support/w/kb/330/kb-1108-how-to-create-a-self-signed-certificate-for-saml-authentication"&gt;assistance regenerating the certificate&lt;/a&gt;.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;&lt;a id="idp"&gt;&lt;/a&gt;IDP&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;If you have made any changes to the SP configurations, these should be matched in the IDP.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;If you have changed the Entity ID, signing certificate or otherwise, you will need to update this on the IDP side&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;After uploading the SP Metadata, and changing any IDP configurations,&amp;nbsp; regenerate the IDP Metadata and download the XML file.&amp;nbsp;If the Metadata is&amp;nbsp;changed, upload the IDP Metadata to the Appian Admin Console.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span&gt;External to Appian, please work with your IDP provider to determine where the IDP references the domain of the SP and change the value to reflect the new hostname.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;If your IDP does not have a field to upload the service provider metadata file. Please see the following resource to assist with &lt;a href="/support/w/kb/370/kb-1153-saml-authentication-faq#My%20identity%20provider%20does%20not%20have%20a%20field%20to%20upload%20a%20service%20provider%20metadata%20file.%20How%20do%20I%20configure%20SAML?"&gt;updating the configurations in the IDP&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;a id="saving-changes"&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-size:150%;"&gt;Saving Changes to SAML Configuration in Appian&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;After changing the SAML configuration in Appian:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Test the connection, using the &amp;ldquo; Test This Configuration&amp;rdquo; button in the top right hand corner of the SAML Configurations page.&amp;nbsp;&lt;/span&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;This is mandatory to save changes if you are signed in with a user in the SAML group, to ensure you do not accidentally log yourself out.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;This is not mandatory if you are not in the SAML group, however it is highly recommended to test with a user in the SAML group, to ensure you do not save invalid configurations. You will be able to save invalid configurations if the user is not in the SAML group.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Choose &amp;ldquo;Done&amp;rdquo; and &amp;ldquo;Save Changes&amp;rdquo; in the lower right hand corner of the &amp;ldquo;SAML Authentication&amp;rdquo; page.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;For further guidance, please see&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/latest/SAML_for_Single_Sign-On.html#how-to-add-a-saml-identity-provider"&gt;SAML configuration in Appian&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;&lt;a id="user-start-pages"&gt;&lt;/a&gt;User Start Pages&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;If you have a &lt;a href="https://docs.appian.com/suite/help/latest/Appian_Administration_Console.html#user-start-pages"&gt;User Start Page&lt;/a&gt;&amp;nbsp;configured, change the user start page configuration to reflect the new domain.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;&lt;a id="recommended"&gt;&lt;/a&gt;Recommended&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Prior to changing the Domain, we recommend ensuring a &lt;a href="https://docs.appian.com/suite/help/latest/SAML_for_Single_Sign-On.html#authentication-group"&gt;system administrator user is outside the SAML group&lt;/a&gt;. If any issues occur the user can access the admin console and disable SAML to allow user access.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;For further questions on SAML see our &lt;a href="/support/w/kb/370/kb-1153-saml-authentication-faq"&gt;SAML FAQ&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;h2 id="mcetoc_1iv3boj6e1"&gt;&lt;span&gt;Affected Versions&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian Cloud.&lt;/p&gt;
&lt;p&gt;Last Reviewed: July 2025&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: SAML, integration, idp, Cloud&lt;/div&gt;
</description></item><item><title>[DRAFT SP-9632] KB-XXXX Transferring SAML after domain change</title><link>https://community.appian.com/support/w/kb/3548/kb-2343-transferring-saml-after-domain-change/revision/8</link><pubDate>Tue, 01 Jul 2025 16:06:56 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:5c48dff1-a413-460d-9ab6-c5b7ec54e999</guid><dc:creator>pauline.delacruz</dc:creator><comments>https://community.appian.com/support/w/kb/3548/kb-2343-transferring-saml-after-domain-change#comments</comments><description>Revision 8 posted to Appian Knowledge Base by pauline.delacruz on 7/1/2025 4:06:56 PM&lt;br /&gt;
&lt;h2 id="mcetoc_1iv3boj6e0"&gt;Purpose&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;SAML is tied to the Service Provider Hostname, hence when changing to a&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/latest/Using_a_Custom_Domain_in_Appian_Cloud.html"&gt;custom domain&lt;/a&gt; there will be required changes to reconfigure aspects of SAML.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;The required steps may vary with the Identify Provider (IDP) or custom configurations, and this KB article is intended to be a guide to assist with the common changes. For further assistance please consult your IDP provider, and reach out to Appian Support through a support case.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Table of Contents:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#appian-saml"&gt;For Appian SAML configurations&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#sp-metadata"&gt;SP Metadata&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#idp"&gt;IDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#saving-changes"&gt;Saving Changes to SAML Configuration in Appian&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#user-start-pages"&gt;User Start Pages&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#recommended"&gt;Recommended&amp;nbsp;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;&lt;a id="appian-saml"&gt;&lt;/a&gt;For Appian SAML configurations&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;The hostname is referenced in:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Service Provider (SP) Metadata&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;The hostname may also be referenced in:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Identity Provider (IDP) Metadata&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Service Provider PEM file Signing Certificate&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;User Start Pages&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;&lt;a id="sp-metadata"&gt;&lt;/a&gt;SP Metadata&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;To regenerate the SP Metadata with the new customer domain:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;By Preference:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Review the Entity ID, and Service Provider Signing Certificate, and change as preferred. These will typically reference the Appian Hostname.&lt;/span&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;The Entity ID does not have to reflect the Hostname, as the Entity ID is a text value. It is important that this value aligns between SP and IDP.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;The Signing Certificate may reflect the hostname in the Common Name.&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Required:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Even if there are no manual changes to the SP Settings, you will still regenerate the SP Metadata to point to the new domain, this is because the location attributes for the SAML assertion reference the hostname.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Once the SP settings are updated, regenerate the SP Metadata, this will download a XML file with the required connection information.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Review the XML metadata file to ensure the old domain is replaced with the new domain, and upload this SP metadata to you IDP.&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Please see the following resource for more information on&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/latest/SAML_for_Single_Sign-On.html#service-provider-metadata"&gt;service provider metadata&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Additionally, please see the following for more &lt;a href="/support/w/kb/330/kb-1108-how-to-create-a-self-signed-certificate-for-saml-authentication"&gt;assistance regenerating the certificate&lt;/a&gt;.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;&lt;a id="idp"&gt;&lt;/a&gt;IDP&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;If you have made any changes to the SP configurations, these should be matched in the IDP.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;If you have changed the Entity ID, signing certificate or otherwise, you will need to update this on the IDP side&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;After uploading the SP Metadata, and changing any IDP configurations,&amp;nbsp; regenerate the IDP Metadata and download the XML file.&amp;nbsp;If the Metadata is&amp;nbsp;changed, upload the IDP Metadata to the Appian Admin Console.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span&gt;External to Appian, please work with your IDP provider to determine where the IDP references the domain of the SP and change the value to reflect the new hostname.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;If your IDP does not have a field to upload the service provider metadata file. Please see the following resource to assist with &lt;a href="/support/w/kb/370/kb-1153-saml-authentication-faq#My%20identity%20provider%20does%20not%20have%20a%20field%20to%20upload%20a%20service%20provider%20metadata%20file.%20How%20do%20I%20configure%20SAML?"&gt;updating the configurations in the IDP&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;a id="saving-changes"&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-size:150%;"&gt;Saving Changes to SAML Configuration in Appian&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;After changing the SAML configuration in Appian:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Test the connection, using the &amp;ldquo; Test This Configuration&amp;rdquo; button in the top right hand corner of the SAML Configurations page.&amp;nbsp;&lt;/span&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;This is mandatory to save changes if you are signed in with a user in the SAML group, to ensure you do not accidentally log yourself out.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;This is not mandatory if you are not in the SAML group, however it is highly recommended to test with a user in the SAML group, to ensure you do not save invalid configurations. You will be able to save invalid configurations if the user is not in the SAML group.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Choose &amp;ldquo;Done&amp;rdquo; and &amp;ldquo;Save Changes&amp;rdquo; in the lower right hand corner of the &amp;ldquo;SAML Authentication&amp;rdquo; page.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;For further guidance, please see&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/latest/SAML_for_Single_Sign-On.html#how-to-add-a-saml-identity-provider"&gt;SAML configuration in Appian&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;&lt;a id="user-start-pages"&gt;&lt;/a&gt;User Start Pages&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;If you have a &lt;a href="https://docs.appian.com/suite/help/latest/Appian_Administration_Console.html#user-start-pages"&gt;User Start Page&lt;/a&gt;&amp;nbsp;configured, change the user start page configuration to reflect the new domain.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;&lt;a id="recommended"&gt;&lt;/a&gt;Recommended&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Prior to changing the Domain, we recommend ensuring a &lt;a href="https://docs.appian.com/suite/help/latest/SAML_for_Single_Sign-On.html#authentication-group"&gt;system administrator user is outside the SAML group&lt;/a&gt;. If any issues occur the user can access the admin console and disable SAML to allow user access.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;For further questions on SAML see our &lt;a href="/support/w/kb/370/kb-1153-saml-authentication-faq"&gt;SAML FAQ&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;h2 id="mcetoc_1iv3boj6e1"&gt;&lt;span&gt;Affected Versions&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian Cloud.&lt;/p&gt;
&lt;p&gt;Last Reviewed: July 2025&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: SAML, integration, idp, Cloud&lt;/div&gt;
</description></item><item><title>[DRAFT SP-9632] KB-XXXX Transferring SAML after domain change</title><link>https://community.appian.com/support/w/kb/3548/kb-2343-transferring-saml-after-domain-change/revision/7</link><pubDate>Tue, 01 Jul 2025 16:01:29 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:5c48dff1-a413-460d-9ab6-c5b7ec54e999</guid><dc:creator>pauline.delacruz</dc:creator><comments>https://community.appian.com/support/w/kb/3548/kb-2343-transferring-saml-after-domain-change#comments</comments><description>Revision 7 posted to Appian Knowledge Base by pauline.delacruz on 7/1/2025 4:01:29 PM&lt;br /&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;SAML is tied to the Service Provider Hostname, hence when changing to a&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/latest/Using_a_Custom_Domain_in_Appian_Cloud.html"&gt;custom domain&lt;/a&gt; there will be required changes to reconfigure aspects of SAML.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;The required steps may vary with the Identify Provider (IDP) or custom configurations, and this KB article is intended to be a guide to assist with the common changes. For further assistance please consult your IDP provider, and reach out to Appian Support through a support case.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;For Appian SAML configurations&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;The hostname is referenced in:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Service Provider (SP) Metadata&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;The hostname may also be referenced in:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Identity Provider (IDP) Metadata&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Service Provider PEM file Signing Certificate&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;User Start Pages&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;SP Metadata&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;To regenerate the SP Metadata with the new customer domain:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;By Preference:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Review the Entity ID, and Service Provider Signing Certificate, and change as preferred. These will typically reference the Appian Hostname.&lt;/span&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;The Entity ID does not have to reflect the Hostname, as the Entity ID is a text value. It is important that this value aligns between SP and IDP.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;The Signing Certificate may reflect the hostname in the Common Name.&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Required:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Even if there are no manual changes to the SP Settings, you will still regenerate the SP Metadata to point to the new domain, this is because the location attributes for the SAML assertion reference the hostname.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Once the SP settings are updated, regenerate the SP Metadata, this will download a XML file with the required connection information.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Review the XML metadata file to ensure the old domain is replaced with the new domain, and upload this SP metadata to you IDP.&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Please see the following resource for more information on&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/latest/SAML_for_Single_Sign-On.html#service-provider-metadata"&gt;service provider metadata&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Additionally, please see the following for more &lt;a href="/support/w/kb/330/kb-1108-how-to-create-a-self-signed-certificate-for-saml-authentication"&gt;assistance regenerating the certificate&lt;/a&gt;.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;IDP&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;If you have made any changes to the SP configurations, these should be matched in the IDP.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;If you have changed the Entity ID, signing certificate or otherwise, you will need to update this on the IDP side&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;After uploading the SP Metadata, and changing any IDP configurations,&amp;nbsp; regenerate the IDP Metadata and download the XML file.&amp;nbsp;If the Metadata is&amp;nbsp;changed, upload the IDP Metadata to the Appian Admin Console.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span&gt;External to Appian, please work with your IDP provider to determine where the IDP references the domain of the SP and change the value to reflect the new hostname.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;If your IDP does not have a field to upload the service provider metadata file. Please see the following resource to assist with &lt;a href="/support/w/kb/370/kb-1153-saml-authentication-faq#My%20identity%20provider%20does%20not%20have%20a%20field%20to%20upload%20a%20service%20provider%20metadata%20file.%20How%20do%20I%20configure%20SAML?"&gt;updating the configurations in the IDP&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;/span&gt;&lt;span style="font-size:150%;"&gt;Saving Changes to SAML Configuration in Appian&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;After changing the SAML configuration in Appian:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Test the connection, using the &amp;ldquo; Test This Configuration&amp;rdquo; button in the top right hand corner of the SAML Configurations page.&amp;nbsp;&lt;/span&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;This is mandatory to save changes if you are signed in with a user in the SAML group, to ensure you do not accidentally log yourself out.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;This is not mandatory if you are not in the SAML group, however it is highly recommended to test with a user in the SAML group, to ensure you do not save invalid configurations. You will be able to save invalid configurations if the user is not in the SAML group.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Choose &amp;ldquo;Done&amp;rdquo; and &amp;ldquo;Save Changes&amp;rdquo; in the lower right hand corner of the &amp;ldquo;SAML Authentication&amp;rdquo; page.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;For further guidance, please see&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/latest/SAML_for_Single_Sign-On.html#how-to-add-a-saml-identity-provider"&gt;SAML configuration in Appian&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;User Start Pages&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;If you have a &lt;a href="https://docs.appian.com/suite/help/latest/Appian_Administration_Console.html#user-start-pages"&gt;User Start Page&lt;/a&gt;&amp;nbsp;configured, change the user start page configuration to reflect the new domain.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;Recommended&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Prior to changing the Domain, we recommend ensuring a &lt;a href="https://docs.appian.com/suite/help/latest/SAML_for_Single_Sign-On.html#authentication-group"&gt;system administrator user is outside the SAML group&lt;/a&gt;. If any issues occur the user can access the admin console and disable SAML to allow user access.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;For further questions on SAML see our &lt;a href="/support/w/kb/370/kb-1153-saml-authentication-faq"&gt;SAML FAQ&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;Affected Versions&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian Cloud.&lt;/p&gt;
&lt;p&gt;Last Reviewed: July 2025&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: SAML, integration, idp, Cloud&lt;/div&gt;
</description></item><item><title>[DRAFT SP-9632] KB-XXXX Transferring SAML after domain change</title><link>https://community.appian.com/support/w/kb/3548/kb-2343-transferring-saml-after-domain-change/revision/6</link><pubDate>Thu, 02 Jan 2025 17:35:23 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:5c48dff1-a413-460d-9ab6-c5b7ec54e999</guid><dc:creator>pauline.delacruz</dc:creator><comments>https://community.appian.com/support/w/kb/3548/kb-2343-transferring-saml-after-domain-change#comments</comments><description>Revision 6 posted to Appian Knowledge Base by pauline.delacruz on 1/2/2025 5:35:23 PM&lt;br /&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;SAML is tied to the Service Provider Hostname, hence when changing to a&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/latest/Using_a_Custom_Domain_in_Appian_Cloud.html"&gt;custom domain&lt;/a&gt; there will be required changes to reconfigure aspects of SAML.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;The required steps may vary with the IDP or custom configurations, and this KB is intended to be a guide to assist with the common changes. For further assistance please consult your IDP provider, and reach out to Appian Support through a support case.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;For Appian SAML configurations&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;The hostname is referenced in:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Service Provider (SP) Metadata&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;The hostname may also be referenced in:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;IDP Metadata&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Service Provider PEM file Signing Certificate&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;User Start Pages&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;SP Metadata&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;To regenerate the SP Metadata with the new customer domain:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;By Preference:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Review the Entity ID, and Service Provider Signing Certificate, and change as preferred. These will typically reference the Appian Hostname.&lt;/span&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;The Entity ID does not have to reflect the Hostname, as the Entity ID is a text value. It is important that this value aligns between SP and IDP.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;The Signing Certificate may reflect the hostname in the Common Name.&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Required:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Even if there are no manual changes to the SP Settings, you will still regenerate the SP Metadata to point to the new domain, this is because the location attributes for the SAML assertion reference the hostname.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Once the SP settings are updated, regenerate the SP Metadata, this will download a XML file with the required connection information.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Review the XML metadata file to ensure the old domain is replaced with the new domain, and upload this SP metadata to you IDP.&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Please see the following resource for more information on&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/latest/SAML_for_Single_Sign-On.html#service-provider-metadata"&gt;service provider metadata&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Additionally, please see the following for more &lt;a href="/support/w/kb/330/kb-1108-how-to-create-a-self-signed-certificate-for-saml-authentication"&gt;assistance regenerating the certificate&lt;/a&gt;.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;IDP&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;If you have made any changes to the SP configurations, these should be matched in the IDP.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;If you have changed the Entity ID, signing certificate or otherwise, you will need to update this on the IDP side&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;After uploading the SP Metadata, and changing any IDP configurations,&amp;nbsp; regenerate the IDP Metadata and download the XML file.&amp;nbsp;If the Metadata is&amp;nbsp;changed, upload the IDP Metadata to the Appian Admin Console.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span&gt;External to Appian, please work with your IDP provider to determine where the IDP references the domain of the SP and change the value to reflect the new hostname.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;If your IDP does not have a field to upload the service provider metadata file. Please see the following resource to assist with &lt;a href="/support/w/kb/370/kb-1153-saml-authentication-faq#My%20identity%20provider%20does%20not%20have%20a%20field%20to%20upload%20a%20service%20provider%20metadata%20file.%20How%20do%20I%20configure%20SAML?"&gt;updating the configurations in the IDP&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;/span&gt;&lt;span style="font-size:150%;"&gt;Saving Changes to SAML Configuration in Appian&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;After changing the SAML configuration in Appian:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Test the connection, using the &amp;ldquo; Test This Configuration&amp;rdquo; button in the top right hand corner of the SAML Configurations page.&amp;nbsp;&lt;/span&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;This is mandatory to save changes if you are signed in with a user in the SAML group, to ensure you do not accidentally log yourself out.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;This is not mandatory if you are not in the SAML group, however it is highly recommended to test with a user in the SAML group, to ensure you do not save invalid configurations. You will be able to save invalid configurations if the user is not in the SAML group.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Choose &amp;ldquo;Done&amp;rdquo; and &amp;ldquo;Save Changes&amp;rdquo; in the lower right hand corner of the &amp;ldquo;SAML Authentication&amp;rdquo; page.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;For further guidance, please see&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/latest/SAML_for_Single_Sign-On.html#how-to-add-a-saml-identity-provider"&gt;SAML configuration in Appian&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;User Start Pages&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;If you have a &lt;a href="https://docs.appian.com/suite/help/latest/Appian_Administration_Console.html#user-start-pages"&gt;User Start Page&lt;/a&gt;&amp;nbsp;configured, change the user start page configuration to reflect the new domain.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;Recommended&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Prior to changing the Domain, we recommend ensuring a &lt;a href="https://docs.appian.com/suite/help/latest/SAML_for_Single_Sign-On.html#authentication-group"&gt;system administrator user is outside the SAML group&lt;/a&gt;. If any issues occur the user can access the admin console and disable SAML to allow user access.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;For further questions on SAML see our &lt;a href="/support/w/kb/370/kb-1153-saml-authentication-faq"&gt;SAML FAQ&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;Affected Versions&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian Cloud.&lt;/p&gt;
&lt;p&gt;Last Reviewed: January 2025&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: SAML, integration, idp, Cloud&lt;/div&gt;
</description></item><item><title>[DRAFT SP-9632] Transferring SAML after domain change</title><link>https://community.appian.com/support/w/kb/3548/kb-2343-transferring-saml-after-domain-change/revision/5</link><pubDate>Fri, 12 Jul 2024 15:49:58 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:5c48dff1-a413-460d-9ab6-c5b7ec54e999</guid><dc:creator>pauline.delacruz</dc:creator><comments>https://community.appian.com/support/w/kb/3548/kb-2343-transferring-saml-after-domain-change#comments</comments><description>Revision 5 posted to Appian Knowledge Base by pauline.delacruz on 7/12/2024 3:49:58 PM&lt;br /&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;SAML is tied to the Service Provider Hostname, hence when changing to a&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/latest/Using_a_Custom_Domain_in_Appian_Cloud.html"&gt;custom domain&lt;/a&gt; there will be required changes to reconfigure aspects of SAML.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;The required steps may vary with the IDP or custom configurations, and this KB is intended to be a guide to assist with the common changes. For further assistance please consult your IDP provider, and reach out to Appian Support through a support case.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;For Appian SAML configurations&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;The hostname is referenced in:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Service Provider (SP) Metadata&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;The hostname may also be referenced in:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;IDP Metadata&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Service Provider PEM file Signing Certificate&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;User Start Pages&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;SP Metadata&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;To regenerate the SP Metadata with the new customer domain:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;By Preference:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Review the Entity ID, and Service Provider Signing Certificate, and change as preferred. These will typically reference the Appian Hostname.&lt;/span&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;The Entity ID does not have to reflect the Hostname, as the Entity ID is a text value. It is important that this value aligns between SP and IDP.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;The Signing Certificate may reflect the hostname in the Common Name.&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Required:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Even if there are no manual changes to the SP Settings, you will still regenerate the SP Metadata to point to the new domain, this is because the location attributes for the SAML assertion reference the hostname.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Once the SP settings are updated, regenerate the SP Metadata, this will download a XML file with the required connection information.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Review the XML metadata file to ensure the old domain is replaced with the new domain, and upload this SP metadata to you IDP.&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Please see the following resource for more information on&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/latest/SAML_for_Single_Sign-On.html#service-provider-metadata"&gt;service provider metadata&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Additionally, please see the following for more &lt;a href="/support/w/kb/330/kb-1108-how-to-create-a-self-signed-certificate-for-saml-authentication"&gt;assistance regenerating the certificate&lt;/a&gt;.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;IDP&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;If you have made any changes to the SP configurations, these should be matched in the IDP.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;If you have changed the Entity ID, signing certificate or otherwise, you will need to update this on the IDP side&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;After uploading the SP Metadata, and changing any IDP configurations,&amp;nbsp; regenerate the IDP Metadata and download the XML file.&amp;nbsp;If the Metadata is&amp;nbsp;changed, upload the IDP Metadata to the Appian Admin Console.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span&gt;External to Appian, please work with your IDP provider to determine where the IDP references the domain of the SP and change the value to reflect the new hostname.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;If your IDP does not have a field to upload the service provider metadata file. Please see the following resource to assist with &lt;a href="/support/w/kb/370/kb-1153-saml-authentication-faq#My%20identity%20provider%20does%20not%20have%20a%20field%20to%20upload%20a%20service%20provider%20metadata%20file.%20How%20do%20I%20configure%20SAML?"&gt;updating the configurations in the IDP&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;/span&gt;&lt;span style="font-size:150%;"&gt;Saving Changes to SAML Configuration in Appian&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;After changing the SAML configuration in Appian:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Test the connection, using the &amp;ldquo; Test This Configuration&amp;rdquo; button in the top right hand corner of the SAML Configurations page.&amp;nbsp;&lt;/span&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;This is mandatory to save changes if you are signed in with a user in the SAML group, to ensure you do not accidentally log yourself out.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;This is not mandatory if you are not in the SAML group, however it is highly recommended to test with a user in the SAML group, to ensure you do not save invalid configurations. You will be able to save invalid configurations if the user is not in the SAML group.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Choose &amp;ldquo;Done&amp;rdquo; and &amp;ldquo;Save Changes&amp;rdquo; in the lower right hand corner of the &amp;ldquo;SAML Authentication&amp;rdquo; page.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;For further guidance, please see&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/latest/SAML_for_Single_Sign-On.html#how-to-add-a-saml-identity-provider"&gt;SAML configuration in Appian&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;User Start Pages&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;If you have a &lt;a href="https://docs.appian.com/suite/help/latest/Appian_Administration_Console.html#user-start-pages"&gt;User Start Page&lt;/a&gt;&amp;nbsp;configured, change the user start page configuration to reflect the new domain.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;Recommended&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Prior to changing the Domain, we recommend ensuring a &lt;a href="https://docs.appian.com/suite/help/latest/SAML_for_Single_Sign-On.html#authentication-group"&gt;system administrator user is outside the SAML group&lt;/a&gt;. If any issues occur the user can access the admin console and disable SAML to allow user access.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;For further questions on SAML see our &lt;a href="/support/w/kb/370/kb-1153-saml-authentication-faq"&gt;SAML FAQ&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;Affected Versions&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;This article applies to all versions of Appian Cloud.&lt;/p&gt;
&lt;p&gt;Last Reviewed: July 2024&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: SAML, integration, idp, Cloud&lt;/div&gt;
</description></item><item><title>[DRAFT SP-9632] Transferring SAML after domain change</title><link>https://community.appian.com/support/w/kb/3548/kb-2343-transferring-saml-after-domain-change/revision/4</link><pubDate>Wed, 19 Jun 2024 23:07:52 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:5c48dff1-a413-460d-9ab6-c5b7ec54e999</guid><dc:creator>camille.savagehansen</dc:creator><comments>https://community.appian.com/support/w/kb/3548/kb-2343-transferring-saml-after-domain-change#comments</comments><description>Revision 4 posted to Appian Knowledge Base by camille.savagehansen on 6/19/2024 11:07:52 PM&lt;br /&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;SAML is tied to the Service Provider Hostname, hence when changing to a&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/24.1/Using_a_Custom_Domain_in_Appian_Cloud.html"&gt;custom domain&lt;/a&gt; there will be required changes to reconfigure aspects of SAML.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;The required steps may vary with the IDP or custom configurations, and this KB is intended to be a guide to assist with the common changes. For further assistance please consult your IDP provider, and reach out to Appian Support through a support case.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;For Appian SAML configurations&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;The hostname is referenced in:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Service Provider (SP) Metadata&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;The hostname may also be referenced in:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;IDP Metadata&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Service Provider PEM file Signing Certificate&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;User Start Pages&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;SP Metadata&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;To regenerate the SP Metadata with the new customer domain:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;By Preference:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;review the Entity ID, and Service Provider Signing Certificate, and change as preferred. These will typically reference the Appian Hostname.&lt;/span&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;The Entity ID does not have to reflect the Hostname, as the Entity ID is a text value. It is important that this value aligns between SP and IDP.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;The Signing Certificate may reflect the hostname in the Common Name.&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Required:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Even if there are no manual changes to the SP Settings, you will still regenerate the SP Metadata to point to the new domain, this is because the location attributes for the SAML assertion reference the hostname.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Once the SP settings are updated, regenerate the SP Metadata, this will download a XML file with the required connection information.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Review the XML metadata file to ensure the old domain is replaced with the new domain, and upload this SP metadata to you IDP.&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Please see the following resource for more information on&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/24.1/SAML_for_Single_Sign-On.html#service-provider-metadata"&gt;service provider metadata&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Additionally, please see the following for more &lt;a href="/support/w/kb/330/kb-1108-how-to-create-a-self-signed-certificate-for-saml-authentication"&gt;assistance regenerating the certificate&lt;/a&gt;.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;IDP&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;If you have made any changes to the SP configurations, these should be matched in the IDP.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;If you have changed the Entity ID, signing certificate or otherwise, you will need to update this on the IDP side&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;After uploading the SP Metadata, and changing any IDP configurations,&amp;nbsp; regenerate the IDP Metadata and download the XML file.&amp;nbsp;If the Metadata is&amp;nbsp;changed, upload the IDP Metadata to the Appian Admin Console.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span&gt;External to Appian, please work with your IDP provider to determine where the IDP references the domain of the SP and change the value to reflect the new hostname.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;If your IDP does not have a field to upload the service provider metadata file. Please see the following resource to assist with &lt;a href="/support/w/kb/370/kb-1153-saml-authentication-faq#My%20identity%20provider%20does%20not%20have%20a%20field%20to%20upload%20a%20service%20provider%20metadata%20file.%20How%20do%20I%20configure%20SAML?"&gt;updating the configurations in the IDP&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;/span&gt;&lt;span style="font-size:150%;"&gt;Saving Changes to SAML Configuration in Appian&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;After changing the SAML configuration in Appian:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;test the connection, using the &amp;ldquo; Test This Configuration&amp;rdquo; button in the top right hand corner of the SAML Configurations page.&amp;nbsp;&lt;/span&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;This is mandatory to save changes if you are signed in with a user in the SAML group, to ensure you do not accidentally log yourself out.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;This is not mandatory if you are not in the SAML group, however it is highly recommended you test with a user in the SAML group, to ensure you do not save invalid configurations. You will be able to save invalid configurations if the user is not in the SAML group.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Choose &amp;ldquo;Done&amp;rdquo; and &amp;ldquo;Save Changes&amp;rdquo; in the lower right hand corner of the &amp;ldquo;SAML Authentication&amp;rdquo; page.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;For further guidance, please see&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/24.1/SAML_for_Single_Sign-On.html#how-to-add-a-saml-identity-provider"&gt;SAML configuration in Appian&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;User Start Pages&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;If you have a &lt;a href="https://docs.appian.com/suite/help/24.1/Appian_Administration_Console.html#user-start-pages"&gt;User Start Page&lt;/a&gt;&amp;nbsp;configured, Change the user start page configuration to reflect the new domain.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;Recommended&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Prior to changing the Domain, we recommend ensuring a &lt;a href="https://docs.appian.com/suite/help/23.1/SAML_for_Single_Sign-On.html#authentication-group"&gt;system administrator user is outside the SAML group&lt;/a&gt;. If any issues occur the user can access the admin console and disable SAML to allow user access.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;For further questions on SAML see our &lt;a href="/support/w/kb/370/kb-1153-saml-authentication-faq"&gt;SAML FAQ&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item><item><title>[DRAFT SP-9632] Transferring SAML after domain change</title><link>https://community.appian.com/support/w/kb/3548/kb-2343-transferring-saml-after-domain-change/revision/3</link><pubDate>Wed, 29 May 2024 01:46:49 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:5c48dff1-a413-460d-9ab6-c5b7ec54e999</guid><dc:creator>camille.savagehansen</dc:creator><comments>https://community.appian.com/support/w/kb/3548/kb-2343-transferring-saml-after-domain-change#comments</comments><description>Revision 3 posted to Appian Knowledge Base by camille.savagehansen on 5/29/2024 1:46:49 AM&lt;br /&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;SAML is tied to the Service Provider Hostname, hence when changing to a&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/24.1/Using_a_Custom_Domain_in_Appian_Cloud.html"&gt;custom domain&lt;/a&gt; there will be required changes to reconfigure SAML.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;The required steps may vary with the IDP or custom configurations, and this KB is intended to be a guide to assist with the common changes. For further assistance please consult your IDP provider, and reach out to Appian Support through a support case.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;For Appian SAML configurations&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;the hostname is referenced in:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Service Provider (SP) Metadata&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;The hostname may also be referenced in:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;IDP Metadata&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Service Provider PEM file Signing Certificate&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;User Start Pages&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;SP Metadata&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;To regenerate the SP Metadata with the new customer domain:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;review the Entity ID, and Service Provider Signing Certificate, and change as required. These will typically reference the Appian Hostname.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Once the SP settings are updated, regenerate the SP Metadata, this will download a XML file with the required connection information.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Please note, even if there are no manual changes to the SP Settings, you will still regenerate the SP Metadata to point to the new domain.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Review the XML metadata file to ensure the old domain is replaced with the new domain, and upload this SP metadata to you IDP.&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Please see the following resource for more information on&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/24.1/SAML_for_Single_Sign-On.html#service-provider-metadata"&gt;service provider metadata&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Additionally, please see the following for more &lt;a href="/support/w/kb/330/kb-1108-how-to-create-a-self-signed-certificate-for-saml-authentication"&gt;assistance regenerating the certificate&lt;/a&gt;.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;IDP&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;To regenerate the IDP Metadata with the new custom domain:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;If you have changed the Entity ID to reflect the new custom domain, you will need to update this on the IDP side&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;After uploading the SP Metadata, and changing the IDP Metadata settings,&amp;nbsp; regenerate the IDP Metadata and download the XML file.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Review the XML metadata file to ensure the old Appian domain is replaced with the new domain, and upload this IDP metadata to Appian SAML configurations.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;If your IDP does not have a field to upload the service provider metadata file. Please see the following resource to assist with &lt;a href="/support/w/kb/370/kb-1153-saml-authentication-faq#My%20identity%20provider%20does%20not%20have%20a%20field%20to%20upload%20a%20service%20provider%20metadata%20file.%20How%20do%20I%20configure%20SAML?"&gt;updating the configurations in the IDP&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;External to Appian, please work with your IDP provider to determine where the IDP references the domain of the SP and change the value to reflect the new hostname.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;Saving Changes to SAML Configuration in Appian&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;After changing the SAML configuration in Appian:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;test the connection, using the &amp;ldquo; Test This Configuration&amp;rdquo; button in the top right hand corner of the SAML Configurations page.&amp;nbsp;&lt;/span&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;This is mandatory to save changes if you are signed in with a user in the SAML group, to ensure you do not accidentally log yourself out.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;This is not mandatory if you are not in the SAML group, however it is highly recommended to ensure you do not save invalid configurations. You will be able to save invalid configurations if the user is not in the SAML group.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Choose &amp;ldquo;Done&amp;rdquo; and &amp;ldquo;Save Changes&amp;rdquo; in the lower right hand corner of the &amp;ldquo;SAML Authentication&amp;rdquo; page.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;For further guidance, please see the following for assistance with &lt;a href="https://docs.appian.com/suite/help/24.1/SAML_for_Single_Sign-On.html#how-to-add-a-saml-identity-provider"&gt;SAML configuration in Appian&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;User Start Pages&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;If you have a &lt;a href="https://docs.appian.com/suite/help/24.1/Appian_Administration_Console.html#user-start-pages"&gt;User Start Page&lt;/a&gt;&amp;nbsp;configured, Change the user start page configuration to reflect the new domain.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;Recommended&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Prior to changing the Domain, we recommend ensuring a &lt;a href="https://docs.appian.com/suite/help/23.1/SAML_for_Single_Sign-On.html#authentication-group"&gt;system administrator user is outside the SAML group&lt;/a&gt;. If any issues occur the user can access the admin console and disable SAML to allow user access.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;For further questions on SAML see our &lt;a href="/support/w/kb/370/kb-1153-saml-authentication-faq"&gt;SAML FAQ&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item><item><title>SP-9632: Transferring SAML after domain change</title><link>https://community.appian.com/support/w/kb/3548/kb-2343-transferring-saml-after-domain-change/revision/2</link><pubDate>Wed, 29 May 2024 01:45:59 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:5c48dff1-a413-460d-9ab6-c5b7ec54e999</guid><dc:creator>camille.savagehansen</dc:creator><comments>https://community.appian.com/support/w/kb/3548/kb-2343-transferring-saml-after-domain-change#comments</comments><description>Revision 2 posted to Appian Knowledge Base by camille.savagehansen on 5/29/2024 1:45:59 AM&lt;br /&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;SAML is tied to the Service Provider Hostname, hence when changing to a&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/24.1/Using_a_Custom_Domain_in_Appian_Cloud.html"&gt;custom domain&lt;/a&gt; there will be required changes to reconfigure SAML.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;The required steps may vary with the IDP or custom configurations, and this KB is intended to be a guide to assist with the common changes. For further assistance please consult your IDP provider, and reach out to Appian Support through a support case.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;For Appian SAML configurations&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;the hostname is referenced in:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Service Provider (SP) Metadata&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;The hostname may also be referenced in:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;IDP Metadata&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Service Provider PEM file Signing Certificate&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;User Start Pages&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;SP Metadata&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;To regenerate the SP Metadata with the new customer domain:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;review the Entity ID, and Service Provider Signing Certificate, and change as required. These will typically reference the Appian Hostname.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Once the SP settings are updated, regenerate the SP Metadata, this will download a XML file with the required connection information.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Please note, even if there are no manual changes to the SP Settings, you will still regenerate the SP Metadata to point to the new domain.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Review the XML metadata file to ensure the old domain is replaced with the new domain, and upload this SP metadata to you IDP.&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Please see the following resource for more information on&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/24.1/SAML_for_Single_Sign-On.html#service-provider-metadata"&gt;service provider metadata&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Additionally, please see the following for more &lt;a href="/support/w/kb/330/kb-1108-how-to-create-a-self-signed-certificate-for-saml-authentication"&gt;assistance regenerating the certificate&lt;/a&gt; &amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;IDP&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;To regenerate the IDP Metadata with the new custom domain:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;If you have changed the Entity ID to reflect the new custom domain, you will need to update this on the IDP side&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;After uploading the SP Metadata, and changing the IDP Metadata settings,&amp;nbsp; regenerate the IDP Metadata and download the XML file.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Review the XML metadata file to ensure the old Appian domain is replaced with the new domain, and upload this IDP metadata to Appian SAML configurations.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;If your IDP does not have a field to upload the service provider metadata file. Please see the following resource to assist with &lt;a href="/support/w/kb/370/kb-1153-saml-authentication-faq#My%20identity%20provider%20does%20not%20have%20a%20field%20to%20upload%20a%20service%20provider%20metadata%20file.%20How%20do%20I%20configure%20SAML?"&gt;updating the configurations in the IDP&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;External to Appian, please work with your IDP provider to determine where the IDP references the domain of the SP and change the value to reflect the new hostname.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;Saving Changes to SAML Configuration in Appian&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;After changing the SAML configuration in Appian:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;test the connection, using the &amp;ldquo; Test This Configuration&amp;rdquo; button in the top right hand corner of the SAML Configurations page.&amp;nbsp;&lt;/span&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;This is mandatory to save changes if you are signed in with a user in the SAML group, to ensure you do not accidentally log yourself out.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;This is not mandatory if you are not in the SAML group, however it is highly recommended to ensure you do not save invalid configurations. You will be able to save invalid configurations if the user is not in the SAML group.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Choose &amp;ldquo;Done&amp;rdquo; and &amp;ldquo;Save Changes&amp;rdquo; in the lower right hand corner of the &amp;ldquo;SAML Authentication&amp;rdquo; page.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;For further guidance, please see the following for assistance with &lt;a href="https://docs.appian.com/suite/help/24.1/SAML_for_Single_Sign-On.html#how-to-add-a-saml-identity-provider"&gt;SAML configuration in Appian&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;User Start Pages&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;If you have a &lt;a href="https://docs.appian.com/suite/help/24.1/Appian_Administration_Console.html#user-start-pages"&gt;User Start Page&lt;/a&gt;&amp;nbsp;configured, Change the user start page configuration to reflect the new domain.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;Recommended&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Prior to changing the Domain, we recommend ensuring a &lt;a href="https://docs.appian.com/suite/help/23.1/SAML_for_Single_Sign-On.html#authentication-group"&gt;system administrator user is outside the SAML group&lt;/a&gt;. If any issues occur the user can access the admin console and disable SAML to allow user access.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;For further questions on SAML see our &lt;a href="/support/w/kb/370/kb-1153-saml-authentication-faq"&gt;SAML FAQ&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item><item><title>SP-9632: Transferring SAML after domain change</title><link>https://community.appian.com/support/w/kb/3548/kb-2343-transferring-saml-after-domain-change/revision/1</link><pubDate>Wed, 29 May 2024 01:37:30 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:5c48dff1-a413-460d-9ab6-c5b7ec54e999</guid><dc:creator>camille.savagehansen</dc:creator><comments>https://community.appian.com/support/w/kb/3548/kb-2343-transferring-saml-after-domain-change#comments</comments><description>Revision 1 posted to Appian Knowledge Base by camille.savagehansen on 5/29/2024 1:37:30 AM&lt;br /&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;SAML is tied to the Service Provider Hostname, hence when changing to a&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/24.1/Using_a_Custom_Domain_in_Appian_Cloud.html"&gt;custom domain&lt;/a&gt; there will be required changes to reconfigure SAML.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;The required steps may vary with the IDP or custom configurations, and this KB is intended to be a guide to assist with the common changes. For further assistance please consult your IDP provider, and reach out to Appian Support through a support case.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;For Appian SAML configurations, the hostname is referenced in:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Service Provider (SP) Metadata&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;The hostname may also be referenced in:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;IDP Metadata&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Service Provider PEM file Signing Certificate&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;User Start Pages&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;SP Metadata&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;To regenerate the SP Metadata with the new customer domain:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;review the Entity ID, and Service Provider Signing Certificate, and change as required. These will typically reference the Appian Hostname.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Once the SP settings are updated, regenerate the SP Metadata, this will download a XML file with the required connection information.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Please note, even if there are no manual changes to the SP Settings, you will still regenerate the SP Metadata to point to the new domain.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Review the XML metadata file to ensure the old domain is replaced with the new domain, and upload this SP metadata to you IDP.&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;For information on the service Provider metadata see: &lt;a href="https://docs.appian.com/suite/help/23.1/SAML_for_Single_Sign-On.html#service-provider-metadata"&gt;https://docs.appian.com/suite/help/24.1/SAML_for_Single_Sign-On.html#service-provider-metadata&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;For assistance regenerating the certificate see: &lt;a href="/support/w/kb/330/kb-1108-how-to-create-a-self-signed-certificate-for-saml-authentication"&gt;https://community.appian.com/support/w/kb/330/kb-1108-how-to-create-a-self-signed-certificate-for-saml-authentication&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;IDP&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;To regenerate the IDP Metadata with the new custom domain:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;If you have changed the Entity ID to reflect the new custom domain, you will need to update this on the IDP side&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;After uploading the SP Metadata, and changing the IDP Metadata settings,&amp;nbsp; regenerate the IDP Metadata and download the XML file.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Review the XML metadata file to ensure the old Appian domain is replaced with the new domain, and upload this IDP metadata to Appian SAML configurations.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;If your IDP does not have a field to upload the service provider metadata file. Please update the configurations in the IDP outline in the following resource:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;a href="/support/w/kb/370/kb-1153-saml-authentication-faq#My%20identity%20provider%20does%20not%20have%20a%20field%20to%20upload%20a%20service%20provider%20metadata%20file.%20How%20do%20I%20configure%20SAML"&gt;https://community.appian.com/support/w/kb/370/kb-1153-saml-authentication-faq#My%20identity%20provider%20does%20not%20have%20a%20field%20to%20upload%20a%20service%20provider%20metadata%20file.%20How%20do%20I%20configure%20SAML&lt;/a&gt;?&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;External to Appian, please work with your IDP provider to determine where the IDP references the domain of the SP and change the value to reflect the new hostname.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;Saving Changes to SAML Configuration in Appian&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;After changing the SAML configuration in Appian:&lt;/span&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;test the connection, using the &amp;ldquo; Test This Configuration&amp;rdquo; button in the top right hand corner of the SAML Configurations page.&amp;nbsp;&lt;/span&gt;&lt;ol&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;This is mandatory to save changes if you are signed in with a user in the SAML group, to ensure you do not accidentally log yourself out.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;This is not mandatory if you are not in the SAML group, however it is highly recommended to ensure you do not save invalid configurations. You will be able to save invalid configurations if the user is not in the SAML group.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-size:inherit;"&gt;Choose &amp;ldquo;Done&amp;rdquo; and &amp;ldquo;Save Changes&amp;rdquo; in the lower right hand corner of the &amp;ldquo;SAML Authentication&amp;rdquo; page.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;For further guidance on Saml configuration in Appian see: &lt;a href="https://docs.appian.com/suite/help/23.1/SAML_for_Single_Sign-On.html#how-to-add-a-saml-identity-provider"&gt;https://docs.appian.com/suite/help/24.1/SAML_for_Single_Sign-On.html#how-to-add-a-saml-identity-provider&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;User Start Pages&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;If you have a user start page configured, Change the user start page configuration to reflect the new domain. See more in: &lt;a href="https://docs.appian.com/suite/help/24.1/Appian_Administration_Console.html#user-start-pages"&gt;https://docs.appian.com/suite/help/24.1/Appian_Administration_Console.html#user-start-pages&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;Recommended&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Prior to changing the Domain, we recommend ensuring a system administrator user is outside the SAML group. If any issues occur the user can access the admin console and disable Saml to allow user access. See more on this recommendation in the following resource: &amp;nbsp; &lt;a href="https://docs.appian.com/suite/help/23.1/SAML_for_Single_Sign-On.html#authentication-group"&gt;https://docs.appian.com/suite/help/23.1/SAML_for_Single_Sign-On.html#authentication-group&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;For further questions on SAML see our SAML FAQ: &lt;a href="/support/w/kb/370/kb-1153-saml-authentication-faq"&gt;https://community.appian.com/support/w/kb/370/kb-1153-saml-authentication-faq&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item></channel></rss>