⚠️ Prerequisite: This article is intended for everyone, however, modifying an employee's technical ID requires the "Edit employee database" permission.
1. What is SSO and what are its benefits 🛜
Imagine SSO (Single Sign-On) as a kind of digital passport 🛂
At Workelo, it allows a user to log in without having to enter their username/password.
Authentication is delegated to an identity provider (IDP) that recognizes Workelo as one of its service providers (SP). If the user already exists in the system (match between the technical ID and the Name ID), they are logged in to Workelo. If the user does not exist, they are redirected to the password login page.
The benefits of SSO 🔓
1. SSO enhances security by requiring unique credentials for each user. This means that a complex password is necessary, making it more difficult for hackers to access sensitive information.
2. If a user leaves the company, simply deactivating their ID at the company account level instantly removes their access to the tools.
3. SSO reduces the risk of phishing attacks, as users do not need to click on links in emails to log in.
4. Finally, SSO can improve compliance with security and privacy regulations by providing detailed audit logs that trace every user's action across all connected systems.
Set up SSO here 👉 Set up SSO ⚙️
2. My employee or my boarder can't log in with SSO
Two possible cases:
A. The employee cannot log in and is redirected to the Workelo login portal.
This means that the technical ID field for this employee does not contain the expected value required to enable authentication on the company side.
You can find this code on the profile page (Account tab, Employees page).
It must be filled in exactly as expected in your SSO configuration (user name). ⚠️ This field is case sensitive.
🕵️♀️ The Technical ID and the Name ID must match exactly as defined internally.
🧑💻 This value is defined and configured by your internal IT team. Please check with them to identify the expected value and make the necessary adjustment in the platform.
👉 As Workelo does not have access to this configuration, our support team will not be able to assist.
💡 If this code is populated via an integration with a third-party tool, make sure that the “Internal ID” field is correctly filled in.
B. An error message appears in your company's colors; contact your internal IT department to grant access to the employee 👷🏻
👉 As Workelo does not have access to this configuration, our support team will not be able to assist.
Examples of messages:
- The signed in user ‘xxx’ is blocked because they are not a direct member of a group with access, nor had access directly assigned by an administrator. Please contact your administrator to assign access to this application.
- Select account does not exist and cannot access the application. The account needs to be added as an external user in the tenant first.