Enterprise single sign-on

Sign in with your company identity provider.

Single sign-on lets people in your organisation sign in to Pyron with the account they already use for other work systems, through your organisation's own identity provider. When you connect one, there is no separate Pyron password to manage, and your provider decides who can reach Pyron.

How SSO sign-in works

When your organisation has configured single sign-on, its sign-in page offers a button to continue with your provider in place of a Pyron password. A person selects it, signs in on your provider's own screen, and returns to Pyron already signed in.

Behind that button, your identity provider confirms who the person is, and Pyron matches them to a Pyron account from the identity your provider sends. The first time someone signs in this way, Pyron creates their account and gives them the starting role you have chosen for new people. Each later sign-in matches them to that same account. If a person already has a Pyron account under the same email, their first single sign-on links to it rather than making a second account.

If your provider runs its own extra verification, such as a second factor, that happens on your provider's screen — Pyron does not ask for it again.

For the step-by-step experience your people see at sign-in, including how it looks when single sign-on is required, see signing in.

Requiring SSO

You can require single sign-on for your organisation. When you do, the email and password fields stop signing people in, and your people reach Pyron through the provider button instead. Every sign-in then runs under your identity provider's control, with its own password rules and verification.

Switch this on once you have confirmed that real people can sign in through your provider. Requiring single sign-on before the connection is proven can leave your team waiting at the sign-in page.

Getting connected

Single sign-on is set up from the security settings in the Setup, so you need administrator access to Pyron to connect a provider.

To connect your provider, you supply:

  • A sign-in protocol — SAML or OIDC, whichever your identity provider uses.
  • The connection details from your provider — the address and credentials it gives you for that protocol. Your provider's own documentation refers to these as its metadata or client details.
  • A starting role for new people — the role Pyron assigns the first time someone signs in through your provider. Single sign-on stays switched off until you choose one.
  • A button label — the wording your people see on the provider button on the sign-in page.

Pyron applies the connection when you save it, and the provider button appears on your sign-in page once the details are in place.

You can also decide how extra verification works. By default, Pyron trusts the verification your provider runs and adds none of its own. If you would rather every person also pass Pyron's multi-factor verification, you can turn that on for single sign-on.

Related

Need a hand? support@techly.au

Pyron Documentation