← Back to Blog

Docebo SAML migration runbook: the 2026 security-standards cutover

DoceboSSO/SAMLGovernanceMigration
Concept illustration for Docebo SAML migration runbook: the 2026 security-standards cutover

Migrating to SAML 2.0: A Guide for European SMEs

As a small to medium-sized enterprise in Europe, you’re likely no stranger to the importance of secure Single Sign-On (SSO) solutions. But with Docebo’s upcoming migration to the latest security standards, it’s time to ensure your SSO configuration is up-to-date.

What does this mean for you?

Don’t worry; we’ve got you covered! In this article, we’ll walk you through the essential steps to migrate your Docebo platform to the 2026 Security Standards. We’ll cover everything from the critical update on SAML Reply URL to platform-specific instructions.

The Critical Update: SAML Reply URL

Let’s start with the most critical aspect of the migration: updating your SAML Reply URL. The legacy ACS (Assertion Consumer Service) URL is being deprecated in favor of a high-performance, secure endpoint.

What you need to know:

SAML 2.0 Auth Flow (2026 Version)

To understand the importance of updating your SAML Reply URL, let’s take a look at the new authentication flow:

sequenceDiagram
    participant U as Learner
    participant SP as Docebo (SP)
    participant IDP as Entra ID/Okta (IdP)
    
    U->>SP: Navigate to /sso/v1/saml/login
    SP->>U: SAML AuthnRequest (Redirect)
    U->>IDP: Present Credentials + MFA
    IDP->>U: SAML Response (Signed Assertion)
    U->>SP: POST to /sso/v1/saml/consume
    SP->>SP: Validate Signature & Claims
    SP->>U: Access Granted (Session Start)

Platform-Specific Instructions

Now that we’ve covered the critical update, let’s explore platform-specific instructions.

Microsoft Entra ID

To set up your Microsoft Entra ID as an Identity Provider:

  1. Go to the Azure portal and navigate to your Entra ID instance.
  2. Click on “SAML” under the “Security” section.
  3. Update the Entity ID, Sign-on URL, and Reply URL with the new values:
    • Entity ID: https://your-domain.docebosaas.com
    • Sign-on URL: https://your-domain.docebosaas.com/sso/v1/saml/login
    • Reply URL: https://your-domain.docebosaas.com/sso/v1/saml/consume

Okta

To set up your Okta instance as an Identity Provider:

  1. Log in to the Okta admin console.
  2. Navigate to “Applications” > “Browse Applications”.
  3. Click on “Docebo SAML 2.0” and edit the application.
  4. Update the Entity ID, Sign-on URL, and Reply URL with the new values:
    • Entity ID: https://your-domain.docebosaas.com
    • Sign-on URL: https://your-domain.docebosaas.com/sso/v1/saml/login
    • Reply URL: https://your-domain.docebosaas.com/sso/v1/saml/consume

Key Takeaways

To ensure a seamless migration:

  1. Update your SAML Reply URL to the new endpoint.
  2. Review and update platform-specific settings for Microsoft Entra ID and Okta.
  3. Schedule your migration at your own pace from July 22, 2026.

Get Ahead of the Migration Curve with J4SGON


Working on this yourself? J4SGON S.L. delivers Docebo Connect, HRIS, SSO and migration work for European organisations — see what a scoped engagement covers or describe your project and we will reply with a written scope.

What the SAML migration looks like for a Spanish SME L&D team

For a Spanish SME running Docebo as the LMS — typically 50-300 learners, an existing identity provider on Microsoft Entra ID or Okta, and a single integration owner who handles every platform-level change — the 2026 SAML migration is a calendar exercise more than an engineering one. Docebo is rolling out the new SAML implementation via Launch Pad opt-in starting July 22, 2026, and the legacy SAML endpoint switches off on October 28, 2026. That is a fourteen-week opt-in window where both old and new flows work in parallel; the SME’s job is to schedule the cutover at a time that fits its change-control rhythm, not at midnight on October 27.

The realistic migration shape for an SME-sized deployment is three sessions across about ten weeks. The first session activates the new SAML in the sandbox tenant, points the IdP at the new Reply URL, runs the SSO flow with one test user, and confirms the attribute mapping for email and branch fields looks correct. The second session activates the new SAML in production during a maintenance window, runs both flows in parallel for one full business week, and watches the Docebo SSO log for 401 or attribute-mismatch errors. The third session disables the legacy flow in the IdP’s Docebo application configuration so the October 28 cutoff arrives as a non-event because the migration is already complete and verified.

For Spanish SMEs claiming a Kit Digital IA/BI voucher up to €12,000 to cover the platform work, the SAML cutover is a deliverable the Agente Digitalizador can scope, document, and hand off as part of a clean engagement. Under INCIBE supply-chain expectations on documented authentication governance — increasingly the default for Spanish SMEs participating in public-sector procurement — the runbook produced during these three sessions is the audit artifact that proves controlled change. The official Docebo documentation lives at help.docebo.com and is the authoritative reference for any field whose behaviour is not obvious from the in-app guidance during the cutover itself.

Tell us what you are integrating or migrating

Send the platform, the systems involved and where you are stuck. You get a written scope back — phases, deliverables and what is out of scope — before anything is billed.

Related Articles