Administration
Signing in with your company account
One password fewer, and leavers are handled automatically.
If your people already sign in to everything with their work account, giving them one more password makes little sense. Single sign-on removes it, and along the way fixes the thing nobody remembers: closing access when someone leaves.
What changes most
It is not the convenience of signing in: it is the leaver. An account still open six months after someone left is the commonest security failure in small companies, and with single sign-on it stops depending on somebody remembering.
| Without it | With it |
|---|---|
| One more password per person | The usual one |
| Leavers handled manually, if remembered | Applied automatically |
| Your password policy does not reach here | Applies as it does everywhere else |
Important
Before enabling it, make sure at least one administrator has an alternative way in. If your identity provider goes down and nobody can sign in, you need a service door.
Watch out
Single sign-on does not distribute permissions on its own: it says who you are, not what you can do. Permissions are still decided here.
Worth knowing
It is worth it from ten or fifteen people upward. Below that, managing accounts by hand costs less than configuring it.
›Does it work with Microsoft or Google?
With the usual identity providers, yes.
›What about people without a work account?
It can coexist with normal sign-in for specific cases.
›Do third-party signers come in this way too?
No. They have no account and do not need one.
A real case
The situation
A seventy-person company finds five open accounts belonging to people who left.
What you do
- Enables single sign-on
- Keeps an alternative route for two administrators
What you get
Later leavers are cut off the same day without anyone having to remember.
The situation
Everyone signs in with a different personal account.
What you do
- Uses the corporate account to sign in
What you get
Joining and leaving follow the company.
The situation
Somebody leaves and their access depends on a personal address.
What you do
- Ties access to the company account
What you get
Departure cuts access.
The situation
Passwords are forgotten constantly.
What you do
- Signs in with the account they already use daily
What you get
There stops being one more password.
The situation
Somebody signs in with two different accounts.
What you do
- Merges into the corporate one
What you get
The history stops splitting.
The situation
The corporate domain changes.
What you do
- Updates the configuration before the change
What you get
Nobody is locked out on the day.
This article answers
- configure single sign-on
- sign in with microsoft or google
- stop users needing another password
- automatically provision users