Duo SSO
Learn how to set up Duo SSO (OIDC) for secure authentication.
cside allows you to create an Duo OIDC application and use it to authenticate users into your cside organization.
When you enable Duo SSO, anyone with your company email domain will be forwarded to authenticate with Duo. This means you can use Duo to scope who can access cside, and when you allow someone, they will automatically be added to your cside organization with no permissions.
Requirements:
- cside Enterprise plan
- Organization Admin role in cside
- An already setup cside organization - the initial admin (you) will be the first user, and will be converted to SSO upon migration.
- Admin access to your Duo account
Navigating to SSO Settings
To access the SSO settings in cside:
- Click on your account at the bottom left corner of the dashboard
- Select View organization

- Select Settings

- Navigate to the SSO tab
Create a Duo OIDC Application
- Go to your Duo Admin console. Head into the Applications > Applications tab.
- Click on the "Add application" button.
- Search for "Generic OIDC Relying Party"
- Click "Add"

Configure Duo OIDC Application
Now we will configure this application to be compatible with cside.
- Enter the name of the application as "cside"
- Under "User Access", select either "Enable for all users" or "Enable only for permitted groups". If you select the latter, ensure that you add the appropriate groups that should have access to cside.
- Scroll past "Metdata" to "Relying Party"
- Under "Sign-In Redirect URLs" enter
https://dash.cside.com/auth/callback/oidc - Under "OIDC Response", select the following scopes:
- openid
- profile
- Scroll to the bottom and click "Save"
Obtain Required Details
You'll need the following information from your Duo application to configure SSO in cside:
- Client ID: Found in the application metadata (e.g.,
DKSYWLEY3UDCDGQFXQ0X) - Client Secret: Found in the application metadata
- Duo Endpoint: Your Duo SSO domain (e.g.,
sso-abc12345.sso.duosecurity.com)

Configure SSO in cside
- Go to the cside dashboard.
- Navigate to the SSO settings as described in Navigating to SSO Settings.
- Click Select Provider (or Change Provider if you already have SSO configured) and select Duo Security.
- Fill in the required fields:
- Email Domain: Your company's email domain (e.g.,
example.com) - this must match the users in your Duo instance - Duo Endpoint: Your Duo SSO domain (without
https://) - Client ID: The Client ID from your Duo application
- Client Secret: The Client Secret from your Duo application
- Email Domain: Your company's email domain (e.g.,
- Click Test Connection to verify the configuration.
- Once verified, click Save SSO Configuration.

Testing Your Configuration
After saving the SSO configuration, you can test it by:
- Opening a new incognito/private browser window
- Navigating to dash.cside.com
- Entering an email address with your configured domain
- You should be redirected to Duo for authentication
Need Help?
If you encounter any issues during setup, contact your cside representative for assistance.
How is this doc?