Single Sign-On (SSO)

Single sign-on makes logging into SafeSend Suite fast, easy, and secure. Users can log in by clicking the Continue with Office 365 button on the log-in page. 

Please note:

Single Sign-On is currently only available for Microsoft Office 365.

Enable Single Sign-On In SafeSend Returns

Single Sign-On must be enabled in SafeSend Suite by an administrator on the account. 

  1. Navigate to the Suite Settings
  2. Click Security and locate Single Sign-On
  3. Toggle the O365 switch button to On. 
  4. Click the Gear icon. 
  5. Select Azure Ad Group(s), SSR Users List, and/or Azure Tenant ID.
    • Enter Group ID or Tenant ID if applicable.
    • See below for more information on how users will proceed with login based on the setting selected. 
  6. Click Add

Enable SSO.png

Logging in 

Important

Depending on the Azure company settings, you may see a permissions pop-up after the first sign-in to SafeSend. 

  • Azure Administrator can check box 'Consent on behalf of your Organization' to allow other users to bypass this screen.

Permissions.png

Azure Ad Group(s)

When this option is used, users will be automatically created in SafeSend and will allow them to log in using their Office 365 credentials. 

  • Approval is not required.
  • Users automatically added will only have the Staff user group. To edit user groups/details, refer to the User Management article. 

Obtain Microsoft Office 365 Group ID

Please note:

A group must be created by a system administrator in Azure and the ID must be added to the Suite settings before registering and adding the enterprise application. 

  1. Log in to the Azure Portal.
  2. Navigate to Active Directory to open the Domain Overview page. 
  3. Click Groups on the left-hand side.
    • Azure 3.png
  4. Enter the name of the group you are looking for in the Search Groups field. 
  5. Copy the Group ID (Object ID) from the Object ID column. 
    • Azure 4-5.png

Register for the SafeSend Suite Enterprise Application

A system administrator will need to add SafeSend as an Enterprise Application before they will have access to add user groups. 

  1. Browse for Enterprise applications from Azure Portals Global Search field.
  2. Once the application is opened, click + New Application. This will take you to the Microsoft Entra Gallery.
  3. Search for SafeSend Suite SSO and click on the application to continue the registration. 
  4. Click Sign up for SafeSend Suite SSO.
  5. The SafeSend site will open, and here you will click Continue with Office 365.
  6. A consent screen will open. Click Accept
    • Administrators can select Consent on behalf of your organization. 
      • If this is not selected, the consent will only apply to the logged-in user. 
      • All remaining users that sign in will have to Accept when they log in using Continue with Office 365

Add Users/Groups to the Enterprise Application

Please note:

A user group must be already created to follow the steps below.

  1. Navigate to Enterprise applications.
  2. Search for SafeSend Returns.
  3. Click +Add User/Groups
  4. Click None Selected from left-hand side.
  5. Select the Group(s) to be added to SafeSend Suite and click Select
  6. The next screen will show all the groups selected. Click Assign.  

If you have any trouble accessing Azure Portal or obtaining your Group ID, please contact Microsoft® Azure Support.

If you see the following error message, your firm will need to upgrade your Microsoft® subscription to a plan that includes Groups, or use the User List option in SafeSend. 

User List

The SSR user list allows existing users to log in using their Microsoft® Office 365 credentials. 

  • The user will need to appear in the Azure Tenants and SafeSend for a successful log-in. 
  • No approval is needed. 
Azure Tenant ID

This option allows you to add your Azure Tenant ID in which all users corresponding to that ID will be allowed to log in using their Office 365 credentials. 

  • If the user is already added as a user in SafeSend, no approval is needed for access. 
  • If the user is NOT already a user in SafeSend, approval is required for the user to access. 

Approve or Deny New Users

The approval (or denial) can be done via email or in the SafeSend Suite app. This is a one-time approval. 

Email

  • The firm admin will receive an email that a new user is requesting access via Microsoft® Office 365.
    • They will have the ability to Approve or Deny those privileges from that email request.  

SSR App

  1. Navigate to Account Management.
  2. Click User Permissions.
  3. Choose Grant Access or Deny for each user.

User permissions.png

Revoke SSO (Single Sign-On) Access

SSO can also be revoked after the user has been given access:

  1. Navigate to User Management.
  2. Find the User you wish to revoke access to then click on the Action(...) menu.
  3. Select Revoke Office 365.
  4. You can choose to revoke access Temporarily or Permanently by choosing the respective option.  
    • Temporarily - The user will lose the ability to sign in via SSO but can request SSO access again. The system admin will have to admit them. 
    • Permanently - The user will lose the ability to sign in via SSO but cannot request access again. To reinstate SSO access the system admin will have to edit the specific user in User Management.
  5. Click Apply Changes.

Revoke_SSO.png

For more information about User Management, see the Firm Settings Setup Guide.

Was this article helpful?
0 out of 0 found this helpful
Have more questions? Submit a request

Comments

0 comments

Article is closed for comments.