Settings and Customization

Activate
When enabled, specialized logon page displays when logging on, allowing a user to log on with SAML.
Easily switch On/Off the SAML Module.
Identity provider
JIT provisioning Option
With JIT provisioning, you can use a SAML Assertion to create users the first time they log in to your concreteCMS from a third-party identity provider. JIT provisioning saves you time and effort because it eliminates the need to provision users or create user accounts in advance. we fetch the user from email (in NameID or Assertion attributes) and if in both cases the user with that email is not found, a new user is created.
You can set the default Group for new JIT users. The default role is None, but you can choose to add new JIT users as Administrators or other new ConcreteCMS created group.
Force authentication
If enabled, users having a current, active SSO session will be re-authenticated by the identity provider .
Sets the ForceAuthn attribute on generated SAML requests, requesting that the IdP re-authenticate the user.
Default After Login Redirect Url
When an unsolicited SSO response arrives at the Service Provider , the user (if authenticated) is redirected to this default URL.
The URL to which SP redirects successfully authenticated end users.

You can customized login page 
Advanced