πŸš€ NEW: sproof's AI assistant for quick integration Learn more

Single Sign On (SSO) πŸ‘‘

πŸ‘‘ Enterprise Feature

Would you like to use this feature? Please contact us to activate it!

πŸ“§ Contact: support@sproof.com
🀝 We look forward to your inquiry!


πŸ’‘ At a glance

Setting up Single Sign On (SSO) handles signing in to sproof Sign via the identity providers used in your company (e.g., Microsoft Entra ID or Shibboleth). This allows access to be controlled centrally and the user experience to be optimized. Since authentication runs entirely through your provider, security mechanisms like Two-Factor Authentication (2FA) can also be managed directly there. This article explains which technical prerequisites must be met and how to configure the security settings.


πŸ“‘ Step-by-step guide

Prerequisites for setting up SSO

To enable SSO for your organization, basic configurations must be made. Please ensure you have the following information ready or forward it to your Customer Success Manager:

  • Target domain(s): Enter all domains that should be managed via SSO (e.g., @yourcompany.com, @yourcompany2.com).

  • Identity provider: Which system do you use (e.g., Microsoft Entra ID)?

  • Excluded email addresses: Define email addresses that should be excluded from SSO, such as shared accounts (e.g., accounting@yourcompany.com) that do not have their own SSO access.

Note: If Microsoft Entra ID is used, signing in with a Microsoft account is often already possible by default. However, the SSO setup described here enforces this method and prevents signing in with email and password for the defined domain.


Setting up Two-Factor Authentication (2FA)

The setup of Two-Factor Authentication for signing in to sproof Sign is a setting that must be configured directly in your identity provider (e.g., Microsoft Entra ID). Since sproof Sign delegates authentication to your provider when SSO is active, all security policies configured there automatically apply.

Proceed as follows to set it up:

  1. Set up SSO in sproof Sign: Ensure that the basic SSO configuration (domain, provider, excluded emails) as described in point 1 is completed and active.

  2. Configure 2FA via Entra ID: Your Entra administrator must now specify in the Conditional Access Policies that multi-factor authentication is required for the sproof Sign application or the corresponding user group.

Once this policy in Entra ID is active, users attempting to sign in via sproof Sign will be prompted by Microsoft to confirm the second factor.


Options for user control in sproof Sign

You have different options to control how new plan members who sign in via SSO are handled:

  • Option 1: Domain wildcard (default): Enable the "Domain management" option in the admin dashboard. All people with the stored domain will be automatically added to your plan on first login. If the quota is exhausted, new licenses will be booked automatically.

  • Option 2: Manual assignment: Disable the wildcard function. You must invite users manually in the dashboard under "License & Team". People who sign in via SSO but were not invited will not end up in your plan.

  • Option 3: Control via Entra ID groups: Create a user group in Entra ID and provide the group ID and tenant ID to sproof Sign. Only members of this group will gain access to the plan.


Administration and restrictions

Once SSO is activated, users of the domain are automatically redirected to the identity provider when logging in. Signing in with an sproof Sign password is no longer possible. If you want to block access for certain people, this must primarily be done in the SSO system.

If a plan member is removed from your SSO (e.g., Active Directory), that person can no longer sign in to sproof Sign. However, the user license in the sproof Sign plan remains occupied for the time being. To free the license and completely delete the user or downgrade them to a Free User, please remove the user manually from the list under "License & Team" or contact Support for complex scenarios.

Last updated: