ReFresh supports single sign-on through SAML 2.0, OpenID Connect, and OAuth 2.0. Google Workspace, Microsoft Entra ID (formerly Azure AD), and Okta are the primary tested providers.
Supported protocols: SAML 2.0, OIDC, OAuth 2.0
Primary tested providers: Google Workspace, Microsoft Entra ID, Okta
SSO is configured per organisation
Setup is included in the Automate onboarding package; available on other tiers via the Integrations area
Configuration involves exchanging metadata between ReFresh and your identity provider
Supported SSO providers
ReFresh supports any identity provider that speaks SAML 2.0 or OIDC/OAuth 2.0. The three providers that have been most thoroughly tested:
Google Workspace (OIDC)
Microsoft Entra ID (formerly Azure AD; SAML 2.0 and OIDC)
Okta (SAML 2.0 and OIDC)
Other identity providers (OneLogin, JumpCloud, Auth0, custom SAML, custom OIDC) work through the same protocol support.
When to use SSO
Use SSO when you want to:
Centralise authentication through your existing identity provider
Enforce password and security policies set in your IdP across ReFresh
Reduce the number of credentials your workforce needs to remember
Provision and deprovision users automatically through your IdP
If you only need basic Google or Microsoft sign-in, the Continue with Google and Continue with Microsoft buttons on the login page already provide that and do not require SSO setup.
Configuring SSO
The expected setup flow is:
Open the Integrations area (accessed via Settings → User Auto-Sync → Go to Integrations, or wherever the Integrations area is in your tenant).
Find your identity provider in the list and click Connect.
Exchange metadata with your provider:
Provide ReFresh's SP metadata (entity ID, ACS URL, sign-in callback) to your IdP
Paste your IdP's metadata, or upload its metadata XML, into ReFresh
Map your IdP attributes to ReFresh fields (email, first name, last name, group membership).
Test sign-in with a test account before rolling out broadly.
Enable SSO for your organisation.
If you need help, contact your ReFresh account contact. SSO configuration is included in the Automate onboarding package.
Related articles
Logging in and navigating ReFresh (1.2)
Connecting an HRIS (2.5)
Multi-factor authentication (2.7)