Skip to main content

Setting up SSO

ReFresh supports single sign-on through SAML 2.0, OpenID Connect, and OAuth 2.0. Google Workspace, Microsoft Entra ID (formerly Azure AD), and Okta are the primary tested providers.

Written by Harrison Kennedy

ReFresh supports single sign-on through SAML 2.0, OpenID Connect, and OAuth 2.0. Google Workspace, Microsoft Entra ID (formerly Azure AD), and Okta are the primary tested providers.

  • Supported protocols: SAML 2.0, OIDC, OAuth 2.0

  • Primary tested providers: Google Workspace, Microsoft Entra ID, Okta

  • SSO is configured per organisation

  • Setup is included in the Automate onboarding package; available on other tiers via the Integrations area

  • Configuration involves exchanging metadata between ReFresh and your identity provider


Supported SSO providers

ReFresh supports any identity provider that speaks SAML 2.0 or OIDC/OAuth 2.0. The three providers that have been most thoroughly tested:

  • Google Workspace (OIDC)

  • Microsoft Entra ID (formerly Azure AD; SAML 2.0 and OIDC)

  • Okta (SAML 2.0 and OIDC)

Other identity providers (OneLogin, JumpCloud, Auth0, custom SAML, custom OIDC) work through the same protocol support.


When to use SSO

Use SSO when you want to:

  • Centralise authentication through your existing identity provider

  • Enforce password and security policies set in your IdP across ReFresh

  • Reduce the number of credentials your workforce needs to remember

  • Provision and deprovision users automatically through your IdP

If you only need basic Google or Microsoft sign-in, the Continue with Google and Continue with Microsoft buttons on the login page already provide that and do not require SSO setup.


Configuring SSO

The expected setup flow is:

  1. Open the Integrations area (accessed via Settings → User Auto-Sync → Go to Integrations, or wherever the Integrations area is in your tenant).

  2. Find your identity provider in the list and click Connect.

  3. Exchange metadata with your provider:

    • Provide ReFresh's SP metadata (entity ID, ACS URL, sign-in callback) to your IdP

    • Paste your IdP's metadata, or upload its metadata XML, into ReFresh

  4. Map your IdP attributes to ReFresh fields (email, first name, last name, group membership).

  5. Test sign-in with a test account before rolling out broadly.

  6. Enable SSO for your organisation.

If you need help, contact your ReFresh account contact. SSO configuration is included in the Automate onboarding package.


Related articles

  • Logging in and navigating ReFresh (1.2)

  • Connecting an HRIS (2.5)

  • Multi-factor authentication (2.7)

Did this answer your question?