Federation establishes a trust relationship between Trimble ID (TID) and your Identity Provider (IdP). This allows your users to sign in using their single sign-on (SSO) organizational credentials, which improves security while removing the need for separate Trimble ID passwords.
Overview
Federation lets your users access Trimble applications with a single set of credentials defined by your organization. By establishing federated authentication, Trimble ID accepts identities from your verified external domain, which reduces credential sprawl and lets you manage users with just-in-time (JIT) provisioning. Trimble ID Federations are a free add-on service for Trimble customers.
During the course of setting up a federation, Trimble collects needed information over several phases. There are prerequisites and key steps. Once configured, the federation will be active across all applications that use Trimble ID for authentication.
Getting Started
- Main contact(s) name and email. This must include a technical contact who has admin access to your company's identity provider (IdP).
- Test user email account(s). These accounts should be employees who have access to the relevant Trimble products but will not be greatly impacted should any issues arise.
- Domain(s) to be federated
- Your organization's Identity Provider (IdP)
- The protocol you intend to use for the federation
- Whether your organization enforces multifactor authentication (MFA)
After you submit the form, Trimble responds by email with next steps. For additional information about supported IdPs and troubleshooting, see Trimble Identity Federation FAQ.
Prerequisites and Requirements
- Technical Compliance: Your organization's IdP must be fully compliant with either the SAML 2.0 protocol or the OIDC protocol.
- End-user Readiness: All users must have an active, accessible email account. This account must match the email address (claim) provided by your identity provider during the sign-in process. This match is required for account verification and JIT provisioning.
- IT Expertise: One or more individuals in your organization will need to be prepared to do the following as part of the federation process:
- Act as liaison between your organization and the federations team in communicating and in exchanging information like metadata and attribute mappings.
- Add the required DNS TXT record to the web domain for domain verification.
- Have administrator access to your identity provider (IdP) and take the steps to configure the federation, including entering specific configuration values that Trimble will provide.
Key Steps
There are four key steps in setting up a federation.

Once you submit the Federation Form, the federations teams will coordinate each step directly with you via email.
Automated User Onboarding
Post-Configuration Considerations
- Expect to test the federation with a small number of pilot users; provide their email addresses when you complete the federation request form.Note: For troubleshooting and solving federation-related issues, the federations team may require information about the activity between Trimble ID and your browser. If this becomes needed, we will provide instructions to one or more of your test users for obtaining HAR files from their web browser, with directions to send them to us.
- Once the federation between your IdP and Trimble ID is configured and deployed, all users with email addresses in the federated domain must use the same single sign-on process to sign in.Important: Domain users will no longer be able to authenticate their sign-in using social identity providers (Google, Apple, and Microsoft).