All topics
Single sign-on Admins
Let your people sign in through your own identity provider, such as Entra ID, Okta or Google Workspace.
An organisation can let its people sign in through its own identity provider — Entra ID, Okta, Google Workspace, ADFS or any other that speaks SAML 2.0. An administrator sets it up at Settings › Single sign-on, which sets out the three steps in order. Click any of the values it shows to copy it.
Setting it up
- In your identity provider, create a SAML application for mapzaa and give it the Entity ID and Reply (ACS) URL shown in step 1 — or all of mapzaa's metadata, if it can read that.
- Have it send each person's email address, as the NameID or as an email attribute.
- Paste your identity provider's metadata XML into Identity provider metadata (XML) and press Save.
- Try it in a private window with the Sign-in link step 3 now shows. The same link belongs in your identity provider's app portal.
Single sign-on only signs in people who already have an account in your organisation, matched by email address. You still invite them as usual, so seats and roles stay yours to decide. Someone whose address has no account is turned away, and the attempt shows in the audit log. Signing in this way skips the emailed code: your identity provider's own checks stand in for it.
If your organisation has its own address, the sign-in page there shows a Sign in with single sign-on button. Elsewhere, people use the sign-in link.
Requiring it
To begin with, passwords keep working alongside single sign-on. Require single sign-on stops everyone but administrators signing in with a password, and new people are invited without choosing one. Everyone but the administrators who is signed in is signed out when you turn it on, so make sure it works first. Allow passwords again reverses it.
Administrators can always use their password. Requiring single sign-on never applies to them, so if your identity provider breaks, someone can still sign in and turn it off.
Turn off removes single sign-on altogether, and everyone signs in with a password again. Members who joined while it was required have no password of their own; they set one with Forgot password?.
Getting your own address later changes the URLs. The Entity ID and Reply URL live on your organisation's own address when it has one. If one is added after single sign-on is set up, update both in your identity provider.
Something not covered here?
Email [email protected] — we usually reply the same day. If you are not set up yet, we will put your municipality on the map in about twenty minutes.