SSO
Set up single sign-on for the tenant with an OIDC identity provider and verify your company's email domains.
With SSO, members sign in to Advisor through your company's identity provider (IdP). Setup has two parts: registering the IdP through OIDC and verifying the email domains that will use it.
Before you start
- You need the
tenants.sso.managepermission. The Tenant Admin role has it. - You need access to your IdP to create an OIDC application.
- To verify a domain, you need access to publish a TXT record in the domain's DNS.
1. Register the identity provider
-
Go to Administração (Administration) > Acesso (Access) > SSO.
-
Under Provedor de identidade (Identity provider), copy the Redirect URI and the Post-logout redirect URI.
-
In your IdP, create an OIDC application and paste the two URIs you copied.
-
Configure the IdP to send the email claim in the ID token.
-
Back in Advisor, fill in the fields:
Field What to enter Issuer (URL) Your IdP's issuer address. It must start with https.Client ID The ID of the application created in the IdP. Client secret The secret of the application created in the IdP. -
Save the configuration.
2. Verify an email domain
SSO applies to emails from verified domains.
-
Under Domínios de e-mail (Email domains), type the domain and select Reivindicar (Claim).
-
In the domain's DNS, publish a TXT record:
Name Value _advisor-verify.<domain>advisor-domain-verification=<token>Advisor shows the token on screen.
-
Once the record is published, select Verificar (Verify).
Domain states
| State | What it means |
|---|---|
| Reivindicado (Claimed) | The domain was registered, but the TXT record has not been confirmed yet. |
| Verificado (Verified) | SSO is available for the domain's emails. Password sign-in still works. |
| Obrigatório (Required) | Emails from this domain can no longer sign in with a password. Sign-in is available only through SSO. |
Session
A session opened through the company SSO lasts 8 hours. After that, the person signs in again through the IdP.
Turn off SSO
When you select Desligar SSO (Turn off SSO), all domains go back to password sign-in and the IdP configuration is erased. To use SSO again, register the provider again.