How To
Summary
Blueworks Live incorporates IBMid authentication to the client organization's Identity Provider to enable SSO.
IBMid is an identity service to allow customers to engage digitally with IBM.
It allows the same credentials to be used across all IBM services such as: IBM support site, forums, request for enhancements (RFE) site, sales and passport advantage sites and many more.
Objective
If the customer's account is enabled with IBM ID, the current user experience is the following:

Once Single Sign On is set up, the new user experience would be the following:

Environment
Blueworks Live
Steps
Steps
You should review all steps in the IBMid SSO Configuration Documentation
https://www.ibm.com/docs/en/ief?topic=welcome-onboarding and work with IBMid support
Working with IBMid Federation Team
(1) Upon confirmation, the IBMid Federation team reaches out to the customer with their Welcome template. It involves information about exchanging metadata files and IBMid federation requirements to create a trust.
(2) IBMid Federation team sends environment-specific instructions for configuring pre-production federation.
Example: Instructions for AzureAD
(3) Testing commences on IBM preProduction with the Client's enterprise
(a) Once IBM ID team confirms that federation is set up in IBM pre-production, the client commences testing by accessing My IBM (https://wwwpoc.ibm.com/myibm/dashboard/)
(b) Once the user's email address is entered it will redirect to the customer's IDP
(c) Customer sees the landing page.
(4) Configure SSO on IBM production (Done by IBM ID team)
The IBMid team can make production changes only on Tuesdays and Fridays of every week. So all production testing needs to be configured before one of those windows.
(5) Customer enables IBM ID on Blueworks Live test account.

For more information, see 'How do I enable IBMid authentication for my account' on this page
(6) If test account login is successful, the customer enables IBMid on the production account. An email is sent to all users. Or the customer sends the notification out to Admins only.

(7) Any users in the customer account who do not have an IBMid is given an IBMid automatically upon the first login (the IBMid Fed team has an option for this).
(8) [Optional] If your BWL account has Viewer licenses enabled, you can enable Just In Time provisioning (JIT) by checking the following box.
With this box checked, any new user is given permission to the account on demand without having to register in the account, if they have the URL to the process.

Additional Information
Troubleshooting
- If a user experiences login issues, it is best that the user checks their access to the corporate network first.
- The email address that a user logs in to Blueworks Live needs to be the same as the email address listed on their AD.
- If the error is thrown from IBM ID, then the IBM ID team looks into it.
For all BWL errors, the client can raise a case via the IBM Support portal at https://www.ibm.com/mysupport/s/?language=en_US
Document Location
Worldwide
[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SS2MKC","label":"IBM Blueworks Live"},"ARM Category":[{"code":"a8m50000000CeZOAA0","label":"Admin Console-\u003ESecurity-\u003ESingle Sign On (SSO)"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Version(s)","Line of Business":{"code":"LOB76","label":"Data Platform"}}]
Was this topic helpful?
Document Information
Modified date:
13 November 2025
UID
ibm16238848