Bitrix24 SSO Setup via SAML 2.0

Our company is engaged in the development, support and maintenance of Bitrix and Bitrix24 solutions of any complexity. From simple one-page sites to complex online stores, CRM systems with 1C and telephony integration. The experience of developers is confirmed by certificates from the vendor.
Showing 1 of 1All 1626 services
Bitrix24 SSO Setup via SAML 2.0
Simple
~1 day
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1361
  • image_bitrix-bitrix-24-1c_fixper_448_0.webp
    Website development for FIXPER company
    949
  • image_bitrix-bitrix-24-1c_development_of_an_online_appointment_booking_widget_for_a_medical_center_594_0.webp
    Development based on Bitrix, Bitrix24, 1C for the company Development of an Online Appointment Booking Widget for a Medical Center
    695
  • image_bitrix-bitrix-24-1c_mirsanbel_458_0.webp
    Development based on 1C Enterprise for MIRSANBEL
    834
  • image_crm_dolbimby_434_0.webp
    Website development on CRM Bitrix24 for DOLBIMBY
    733
  • image_crm_technotorgcomplex_453_0.webp
    Development based on Bitrix24 for the company TECHNOTORGKOMPLEKS
    1076

We set up SSO (Single Sign-On) for Bitrix24 so your employees can forget about multiple passwords. Imagine: morning, an employee logs into Windows — one password, opens email — another, accesses Jira — a third, then Bitrix24 — a fourth. Passwords are lost, written on sticky notes, and IT spends hours on resets. SSO solves this: one login via a corporate Identity Provider, like Azure AD, Keycloak, or ADFS — and access to all systems. We implement single sign-on turnkey, with guaranteed compatibility and full documentation. Our experience: over 7 years on the market, 80+ successful projects on Bitrix24 and corporate integrations. Request a consultation — we'll assess your project within 1 day and offer the optimal solution.

How SSO for Bitrix24 works

Bitrix24 supports single sign-on via the SAML 2.0 protocol (Security Assertion Markup Language), a standard defined by OASIS. The workflow:

  1. User opens Bitrix24.
  2. B24 redirects to the Identity Provider (IdP) — Azure AD, Keycloak, ADFS.
  3. User authenticates on the IdP (or is already authenticated via Kerberos).
  4. IdP returns a SAML assertion — a signed XML document with user data.
  5. B24 verifies the signature, extracts attributes, creates or updates the session.

For cloud Bitrix24, SAML SSO is available on Professional and Enterprise tariffs. For on-premise, via the SSO module.

According to 1С-Битрикс documentation, SSO is supported on Professional and Enterprise tariffs.

Configuration on the Identity Provider side

Regardless of the specific IdP, you need to register Bitrix24 as a Service Provider (SP):

SP Parameter Value
Entity ID https://your-domain.bitrix24.by
ACS URL https://your-domain.bitrix24.by/bitrix/tools/saml/acs.php
SLS URL https://your-domain.bitrix24.by/bitrix/tools/saml/sls.php
NameID Format urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress

Azure AD — register an Enterprise Application, configure SAML, upload Federation Metadata XML. Claim rules: user.mail → NameID, user.displayname → Name, user.department → Department.

Keycloak — create a client with SAML protocol, specify Valid Redirect URIs, configure mappers for attributes. Keycloak is convenient for companies that want to host IdP on their own server.

ADFS — add a Relying Party Trust, configure Claim Issuance Policy. A typical issue: the signing certificate expires — you need to monitor the expiration and update it in B24 settings.

Provider Setup Complexity Licensing Features
Azure AD Medium Included in Microsoft 365 Built-in integration with Office 365
Keycloak Low-Medium Open Source Most flexible, can be deployed on-premise
ADFS High Requires Windows Server Deep integration with Active Directory

Certificate exchange

SAML relies on trust between SP and IdP, confirmed by certificates:

  • IdP certificate — uploaded to Bitrix24 SSO settings. B24 uses it to verify SAML assertions. When the IdP certificate rotates, you must update it in B24, otherwise authorization breaks.
  • SP certificate (optional) — if the IdP requires signed AuthnRequest. Generated in B24 settings and uploaded to the IdP.

Recommendation: during IdP certificate rotation, support both old and new certificates for a transition period.

User attribute mapping

The SAML assertion contains user attributes. B24 extracts them and populates the profile:

  • NameID (email) → user login in B24
  • FirstName / LastName → first and last name
  • Department → department (if mapping to B24 structure exists)
  • Groups → groups and roles (for automatic permission assignment)

If a user with that email does not exist in B24, they are created automatically on first login (provisioning via SSO). This is configurable: you can allow auto-creation or require prior registration.

Why configure single sign-on?

The average IT department spends up to 4 hours per week on password resets and account support. SSO reduces this time by 90%. Plus, security improves: no passwords transmitted over the network, centralized access policy. Employees don't write passwords on sticky notes, and system access is immediately revoked upon termination. Compare: deploying Keycloak takes 1-2 days, while ADFS requires setting up Windows Server and configuration, which is 2-3 times longer. Azure AD is a compromise if the company already uses Microsoft 365.

What's included

  • Audit of current infrastructure and selection of Identity Provider.
  • Registration of Bitrix24 as a Service Provider.
  • SAML 2.0 configuration on the IdP side.
  • Certificate exchange and trust testing.
  • Attribute mapping: email, name, department, groups.
  • Automatic user provisioning setup.
  • Operations documentation and certificate rotation procedure.
  • Administrator training.

Process

  1. Analysis — we study your infrastructure, select the appropriate IdP.
  2. Design — we develop the SSO scheme, agree on mapping.
  3. Implementation — we configure the SAML connection, exchange certificates.
  4. Testing — we verify authorization, debug errors.
  5. Deployment — we hand over documentation, conduct training.

Timeline and cost

Cost is calculated individually, depending on the chosen Identity Provider and required integration depth. Estimated timeline: from 3 to 10 business days. Get an accurate estimate — contact us.

Over 7 years on the market, 80+ successful projects on Bitrix24 and corporate integrations — we guarantee quality and post-deployment support. Reach out for a free consultation — we'll propose a solution tailored to your infrastructure.

How a corporate portal on Bitrix24 solves the problem of information chaos?

Employees spend up to 2 hours a day searching for files, emails, and solutions. Tasks get lost in dozens of chats, approvals get stuck for weeks. The manager learns about missed deadlines only at a meeting. A corporate portal on Bitrix24 ties every message, document, and task to a single context. You get a transparent picture of work: who is working on what, which stages, where bottlenecks are. Wikipedia: Information silo describes how unorganized data reduces productivity – a portal cuts that loss by 60–70%.

We will evaluate your project for free – contact us to get the architecture in 2 days. A medium‑sized company typically saves 2.5 million rubles annually after deployment (based on our projects).

What does the portal offer in daily work and why is it better than messengers?

In messengers, information is unstructured – discussions get buried within a week. On the portal, every message is tied to a task, project, or document. Employees spend up to 30% of their work time searching for data (McKinsey). The portal reduces this time by 2–3 times thanks to structured repositories and full‑text search.

Communications. Activity stream, messenger, and video calls are tied to specific tasks. Any discussion can be found six months later – in a messenger it would be buried within a week.

Tasks and projects. Kanban, Gantt, checklists, dependencies, time tracking. Each employee's efficiency is visible in reports – no need to wait for a meeting.

Document flow. Approval routes through the business process designer: leave request → manager → HR → accounting. Electronic signature, versioning, deadline control. Integration with electronic document management (SBIS, Diadoc) via REST API.

HR. Onboarding of new employees, leave/travel requests, organizational structure, absence schedule. An employee knows where to go from day one.

Knowledge base. Bitrix24 wiki engine: regulations, instructions. Knowledge does not leave with departing employees.

Implementation example. For a manufacturing company with 320 employees, we deployed a portal with integration of 1C:SALARY AND HR MANAGEMENT and Active Directory in 4 months. Travel request approval time decreased from 3 days to 4 hours. Savings on employee idle time amounted to 1.5 million rubles per year. Managers receive automatic reports on department efficiency. Customer response time decreased by 20%. Portal payback period is 7 months.

How does integration with 1C and Active Directory accelerate HR management?

Integration with 1C:Enterprise via the b24connector module or custom REST handler: a leave request is approved on the portal through a business process and automatically enters 1C:SALARY AND HR MANAGEMENT for vacation pay calculation. Active Directory (SSO via the ldap module) – the employee account is created once in AD and synchronized to the portal, email, VPN. Upon dismissal, it is blocked everywhere. Manual account creation is eliminated, errors are minimized.

Types of corporate portals and key integrations

Type Purpose Key Feature
Intranet Internal communications and services News, phone directory (sync with AD), meeting room booking, IT requests via BP
HR portal HR management and development Profiles, KPI/OKR on custom HL blocks, training, electronic document flow
Knowledge portal Documentation and regulations Categorization, tags, ratings, subscriptions to updates
Extranet Work with partners and contractors Granular permissions via CGroup and extranet module, access without VPN
Holding portal Management of multi‑company structure Separate workspaces, consolidated reporting, cross‑cutting BPs

Additional integrations that deliver real value:

  • Email: Exchange via EWS API or IMAP, calendar synchronization, creating a task from an email.
  • IP telephony: Asterisk, Mango Office, Zadarma via REST API – calls from the portal, contact card, call recording.
  • Video conferencing: built‑in video calls or integration with Zoom/Teams via marketplace.
  • EDI: SBIS, Diadoc via REST API – fully electronic document flow with counterparties.

Security and compliance with Federal Law 152‑FZ

The portal contains personal data, financial reports, strategic plans. We guarantee protection:

  • role model via CGroup and section‑level permissions;
  • two‑factor authentication (OTP, Yandex.Key, SMS);
  • audit of all actions (b_event_log);
  • TLS encryption for transmission and disk encryption;
  • full compliance with Federal Law No. 152‑FZ "On Personal Data".

How is implementation carried out? Step‑by‑step plan

Stage Duration What we do
1. Audit 2–3 weeks Interviews, process analysis, architecture, integration plan
2. Setup and customization 3–6 weeks Structure, roles, BPs, branding (CSS template)
3. Integrations 2–4 weeks 1C, AD, email, telephony, EDI
4. Data migration 1–2 weeks Documents, directories, employees from current systems
5. Training and pilot 1–2 weeks Administrators, key users, pilot of 20–30 people
6. Scaling 2–4 weeks Connecting departments, fine‑tuning based on feedback
  1. Audit — we record current processes, measure time losses.
  2. Design — choose portal type, plan integrations.
  3. Implementation — configure business processes, permissions, interface.
  4. Test — pilot group tests scenarios, we fix issues.
  5. Launch — connect all employees, train, hand over documentation.

What you receive after implementation

  • Project documentation: architecture, integration scheme, business process diagrams.
  • Configured portal with all integrations (1C, AD, telephony, EDI).
  • Business process descriptions and instructions for administrators and users.
  • 30 days of technical support after launch.
  • Access to our knowledge base and migration scripts.

Post‑launch support: how to prevent the portal from becoming obsolete

After six months, many portals become abandoned. To avoid this, we offer packages with fixed SLA and a dedicated administrator. Performance monitoring, platform updates, user administration, development of new modules. Our team has over 10 years of experience and more than 50 implemented corporate portals on Bitrix24. We are a certified 1C‑Bitrix partner, guaranteeing quality and deadlines.

Mobile access. Native Bitrix24 app (iOS/Android) with push notifications, tasks, chats. Responsive web interface for extranet users (no app installation required). Offline access to documents and tasks, sync when connectivity is restored.

Order a turnkey corporate portal implementation

Schedule a free audit – we will evaluate your project, propose architecture, and give clear timelines. Get a comprehensive proposal and see that the portal pays for itself within the first six months. Contact us today.