Recruitment Marketing Public
SSO Overview
Single sign-on (SSO) is a way for users to be authenticated for multiple applications and services at once. With SSO, a user signs in at a single login screen and can then use a number of apps. Users do not need to confirm their identity with every single service they use.
This SSO can be Service Provider initiated (SP-initiated) or Identity Provider-initiated (IdP-initiated). The main difference between IdP-initiated SSO and SP-initiated SSO is where users start the login process. IdP-initiated login requests start in the identity provider, whereas SP-initiated login requests start in the application users want to access (in this case, Recruitment Marketing).
SP-initiated SSO login process in Recruitment Marketing
The first login screen only requires users to introduce their email address in the field and click "Continue".
Based on this email address, the system will check whether the user has a password account (traditional login using email and password), a SAML account (to login via SSO) or both.
Depending on what type of account they have, different scenarios might occur:
If the user has both types of accounts, they will be redirected to another screen where they will be able to choose if they want to login using their password or via SSO, as per the screenshot below:
Clicking on "Login via SSO" will trigger the SP-initiated SSO and users will be briefly redirected to their IdP that will verify they are who they claim to be. They will then be automatically redirected back to Recruitment Marketing as a logged-in user. However, if they click on "Login via email and password", they will be redirected to a login page like in the screenshot below.
If the user only has a password account. they will be redirected to the above login page so that they can sign in using their credentials.
If the user only has a SAML account, they will be automatically redirected to their IdP for identity verification and then redirected back to Recruitment Marketing where they will be automatically signed in.
Considerations
Please note that in order to benefit from this login via SSO, there is additional configuration needed (SAML). For guidance on how to setup SAML 2.0 in Recruitment Marketing, please refer to the following articles:
Configuring SAML 2.0 SSO with Okta as iDP in Recruitment Marketing
Configuring SAML 2.0 SSO for users with Entra ID (formerly Azure AD) as iDP in Recruitment Marketing
Comments
Article is closed for comments.