Account settings

Customize your Hubstaff account to fit your business needs.

10 minutes

Configuring Single Sign-on (SSO)

In this article, you will learn how to configure Single Sign-on or SSO with your preferred identity provider. Single sign-on works with popular identity providers such as Azure, ADFS, Okta, OneLogin, Google Workspace, and Office 365 to provide an additional layer of access security for you and your team.

Available only on Enterprise plans.
If you’re trying to configure SCIM, click here.

How to enable single sign-on for your organization

To enable SSO, follow the steps below:

Step 1

Navigate to Settings > All settings.

settings all settings

Step 2

Click on Security & Login.

security and login

Step 3

Click on the Configure SSO button.

configure SSO button

Step 4

Copy both the Identifier (Entity ID), and Reply URL (Assertion Consumer Service URL) contents (from the Hubstaff SSO setup page) into the relevant fields in your identity provider’s SAML setup page.

configure sso dialog1

Here is what the setup page looks like in Microsoft Azure:

azure saml

Step 5

Enter the Issuer ID, SSO URL and Identity Provider Certificate (Base64 certificate required).

configure SSO dialog2

In MS Azure, for example, Issuer ID is Microsoft Entra Identifier, SSO URL is the Login URL, and the Certificate certificate to be pasted, or uploaded from Azure.

azure sso setup

You can add up to 10 domains. We restrict the use of popular domains such as Google.com, Hotmail.com, etc.. We require Enterprise users to use their own domain.

Below are guides on how to get SAML/XML data per platform:

Platform Instructions
ADFS https://docs.microsoft.com/en-us/power-apps/maker/portals/configure/configure-saml2-settings
Azure https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/add-application-portal-setup-sso
Okta https://help.okta.com/en-us/Content/Topics/Security/idp-add-saml.htm
OneLogin https://onelogin.service-now.com/support?sys_id=93f95543db109700d5505eea4b96198f&view=sp&id=kb_article&table=kb_knowledge
Google Workspace https://support.google.com/a/answer/6087519?hl=en
Office 365 https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-fed-saml-idp

Step 6

Once configured, you will see the SSO setting enabled. Optional: you can also toggle the Require SSO log in setting to require all users to login using SSO.

sso configured


Login using SSO

Once single sign-on is enabled in your organization, users will be able to sign in with SSO.

Dashboard

Step 1

To sign in to your account using SSO, click on Log in with SSO.

log in with SSO

Step 2

Next, enter your email address, then click Log in.

sign in SSO

Applications

Step 1

When SSO is enabled, you will be redirected to the web login page upon clicking Log into your account.
desktop app SSO login

Step 2

Next, click Continue login to complete the authentication process.

SSO app login

Back to top