IBM Support

Configuring Single Sign-On in Blueworks Live with IBM ID Authentication

How To


Summary

Blueworks Live incorporates IBMid authentication to the client organization's Identity Provider to enable SSO. 

IBMid is an identity service to allow customers to engage digitally with IBM.
It allows the same credentials to be used across all IBM services such as: IBM support site, forums, request for enhancements (RFE) site, sales and passport advantage sites and many more.

Objective

This document is intended to detail the steps required to onboard accounts to federate with IBMid and Blueworks Live account.

If the customer's account is enabled with IBM ID, the current user experience is the following:
 
Using IBMid
 
 
Once Single Sign On is set up, the new user experience would be the following:
 
SSO set up
 
 

Environment

Blueworks Live

Steps

 
Steps
 

You should review all steps in the IBMid SSO Configuration Documentation
https://www.ibm.com/docs/en/ief?topic=welcome-onboarding and work with IBMid support

 
Working with IBMid Federation Team
 
(1) Upon confirmation, the IBMid Federation team reaches out to the customer with their Welcome template. It involves information about exchanging metadata files and IBMid federation requirements to create a trust.
 
(2) IBMid Federation team sends environment-specific instructions for configuring pre-production federation. 
Example: Instructions for AzureAD
 
(3) Testing commences on IBM preProduction with the Client's enterprise
      (a) Once IBM ID team confirms that federation is set up in IBM pre-production, the client commences testing by accessing My IBM (https://wwwpoc.ibm.com/myibm/dashboard/)
      (b) Once the user's email address is entered it will redirect to the customer's IDP
      (c) Customer sees the landing page.
 
(4) Configure SSO on IBM production (Done by IBM ID team)
The IBMid team can make production changes only on Tuesdays and Fridays of every week. So all production testing needs to be configured before one of those windows.
 
 
(5) Customer enables IBM ID on Blueworks Live test account.
image 5366
 
 
(6) If test account login is successful, the customer enables IBMid on the production account. An email is sent to all users. Or the customer sends the notification out to Admins only.
 
image 5370
 
(7) Any users in the customer account who do not have an IBMid is given an IBMid automatically upon the first login (the IBMid Fed team has an option for this).
 
(8) [Optional] If your BWL account has Viewer licenses enabled, you can enable Just In Time provisioning (JIT) by checking the following box.
With this box checked, any new user is given permission to the account on demand without having to register in the account, if they have the URL to the process.
image 5378
 
 

Additional Information

Troubleshooting
 
  • If a user experiences login issues, it is best that the user checks their access to the corporate network first.
  • The email address that a user logs in to Blueworks Live needs to be the same as the email address listed on their AD.
  • If the error is thrown from IBM ID, then the IBM ID team looks into it.
 
For all BWL errors, the client can raise a case via the IBM Support portal at https://www.ibm.com/mysupport/s/?language=en_US

Document Location

Worldwide

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SS2MKC","label":"IBM Blueworks Live"},"ARM Category":[{"code":"a8m50000000CeZOAA0","label":"Admin Console-\u003ESecurity-\u003ESingle Sign On (SSO)"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Version(s)","Line of Business":{"code":"LOB76","label":"Data Platform"}}]

Document Information

Modified date:
13 November 2025

UID

ibm16238848