Skip to main content

Configuring Single Sign-On (SSO)

Configure SSO to allow users to sign in to HINDSITE using your organisation's identity provider.

Written by Rory Broadbridge

SSO allows members of your organisation to access HINDSITE using their company credentials.

HINDSITE supports SAML 2.0 compatible identity providers such as Microsoft Entra ID (Azure AD), Okta, Google Workspace and others.

To configure SSO, navigate to Settings then click on Identify Provider.


Service Provider Configuration

You'll need to register HINDSITE as an application in your identity provider.

This includes:

  • Reply URL (Assertion Consumer Service)

  • Service-provider Entity ID

  • Service Provider Metadata


Import from Your Identity Provider

If your identity provider provides a Metadata URL, you can paste it into the IdP Metadata URL field and select Fetch and Fill.

HINDSITE will automatically populate the required identity provider settings.


Identity Provider Details

If automatic import isn't available, you can manually configure your identity provider settings.

The required fields are:

  • Identity-provider Entity ID

  • Sign-in URL

  • NameID Format

  • Signing Certificate(s)

These values are supplied by your identity provider.


SSO Enforcement

Once SSO has been configured, choose how it should be enforced for members of your organisation.

There are three enforcement options available:

Enforcement Option

Description

Optional

SSO is available but not required. Users can choose to sign in using SSO or continue using their HINDSITE email address and password.

Required for all members

Every member of your organisation must sign in using SSO. Users will no longer be able to authenticate using a HINDSITE password, and password management is handled entirely by your identity provider.

Required for members of specific email domains

Require SSO only for users whose email address matches one or more specified domains.

For example:

  • @company.com → Must sign in using SSO.

  • @contractor.com → Can continue using a HINDSITE email address and password.

The Required for members of specific email domains option is ideal when work can be done by a mix of internal employees and external users such as contractors, customers or suppliers. Internal employees can continue to use your identity provider, while external users can create and manage their own HINDSITE passwords.

Did this answer your question?