Legacy SSO End of Life (EOL) effective August 31, 2026
Effective August 31, 2026, Legacy SSO (SSO 1.0) has been retired for all organizations that did not migrate to SSO 2.0
What this means for you
To reset a password, see Reset your BBID password.
If your organization completed the SSO 2.0 migration before the deadline, this change does not affect you. You can continue signing in through your identity provider as usual.
Why this change happened
As part of ongoing efforts to improve security and user management, Bluebeam retired Legacy SSO and transitioned customers to SSO 2.0 with SCIM. SSO 2.0 offers enhanced scalability, functionality, and efficiency, while giving organizations full control over user management and configuration.
Benefits of transitioning to SSO 2.0
Transitioning to SSO 2.0 provides you with the following benefits:
-
Self managed client secrets mean expirations will no longer be an issue
-
Better security with domain validation
-
The ability to enable SCIM for automated user provisioning and deprovisioning
-
The ability to enable or disable SSO and SCIM from Org Admin
What to do if you didn't migrate to SSO 2.0 before August 31, 2026
If your organization did not migrate from Legacy SSO to SSO 2.0, Legacy SSO is now permanently disabled. To restore SSO access for your users, do the following:
-
See our SSO 2.0 migration FAQ for details.
-
Review Configuring SSO and SCIM for Bluebeam Accounts documentation for more information on setting up SSO 2.0.
-
In the meantime, users can continue signing in using the standard sign-in flow (email and password). To reset a password, see Reset your BBID password.
-
Contact us if your organization would like to set up SCIM.
SSO 2.0 migration FAQs
As part of our ongoing efforts to improve security and user management, we retired Legacy SSO and transitioned customers who initiated a migration to SSO 2.0 with SCIM. In addition, SSO 2.0 offers enhanced scalability, functionality, and efficiency, while providing full control over user management and configuration.
Legacy SSO (SSO 1.0) reached end of life on August 31, 2026. Bluebeam has turned off Legacy SSO for all organizations that did not migrate to SSO 2.0 and reset the standard Bluebeam password for every affected user. Users now sign in through the standard sign-in flow (email and password) unless and until SSO 2.0 is configured.
Bluebeam officially supports SSO configuration for the following IdPs:
-
Microsoft Entra ID: If you use Microsoft Entra ID as an IdP, see Configuring SSO for Bluebeam Accounts | Entra ID.
-
Okta Workforce Identity Cloud: If you use Okta Workforce Identity Cloud as an IdP, see Configuring SSO for Bluebeam Accounts | Okta Workforce Cloud.
Revu is compatible with other IdPs that use OpenID Connect (OIDC) as an authentication protocol, but those configurations aren't supported, and SCIM enablement isn't available. Bluebeam Support won't be able to troubleshoot if you have issues configuring SSO for an unsupported IdP, and you may need to disable SSO.
The ability to configure SSO is only available if your organization:
- Has purchased or converted a minimum of 10 seats to a Bluebeam subscription plan.
- Is not already configured to use SSO with Bluebeam products and services. If your organization already has SSO configured, contact us before continuing.
- Uses Microsoft Entra ID or Okta Workforce Identity Cloud as an identity provider (IdP).
Other IdPs are compatible but not supported. For more information, click here.
Only users with the IT Admin role in Org Admin and the Tenant Admin role on the tenant can configure SSO and SCIM. The Org Admin who requests SSO will automatically be made an IT/Tenant Admin.
-
Minimum seats: 10
-
Maximum domains: 500 per SSO configuration
-
SSO support level: Parent account (but inherited by child accounts)
-
SCIM support:
-
Parent account only
-
Users must all be under one account
-
Users must all be using the same license region
-
-
Multi-tenant: Not supported (separate parent accounts required)
-
Child account SCIM: Not supported
After SSO 2.0 is set up, SSO will be set up across all regions. All users will be able to sign in as they were able to previously do so.
No. Bluebeam doesn't currently support multiple tenant configurations under a single organization.
If you need independently managed SSO and SCIM for different business units or subsidiaries, the following applies:
-
You must split those tenants into separate parent accounts with separate Org Admin accounts.
-
Each parent account would have its own SSO and SCIM configuration.
No. Each organization manages its own SSO and SCIM setup through the parent account. Child accounts inherit configurations from the parent account configuration.
If you need separate SSO and SCIM configurations for child accounts, you must restructure your accounts so each child company becomes a parent account with a separate Org Admin account.