Single Sign-On
Let your users sign in to Xelon HQ with their Microsoft (Entra ID) credentials, with permissions driven by Entra group membership.
Xelon HQ supports organization-level Single Sign-On (SSO) using the SAML 2.0 protocol. Xelon HQ acts as the Service Provider (SP) and Microsoft Entra ID (formerly Azure Active Directory) acts as the Identity Provider (IdP). SSO is configured per organization from the Microsoft Authentication card on the organization detail page.
Microsoft Entra (SAML) SSO Setup
End-to-end setup: create the Entra application, exchange SP/IdP URLs, upload the signing certificate, verify domains, map groups to permission bundles, create breaking-glass users, and enable SSO.
Troubleshooting
Why the Microsoft button does not appear, what the login-page errors mean, certificate and issuer mismatches, group/permission rejections, Graph sync failures, and breaking-glass recovery.
Key characteristics
- SAML 2.0 — not OAuth / OpenID Connect.
- Just-in-time provisioning — a Xelon HQ user is created automatically on first successful login. There is no user import step.
- Group-based permissions — access comes from Entra security-group membership, mapped to Xelon HQ permissions through Group → Permission Bundles. Membership is re-evaluated on every login.
- Password login is blocked for every user on a verified SSO domain once SSO is enabled — except breaking-glass accounts listed under Password Login Exceptions.
- SHA-256 or stronger signatures only. SHA-1 assertions are rejected.
Turn on the Enable SSO toggle only after every required section is configured and at least one breaking-glass user exists. Enabling SSO with an incomplete or wrong configuration can lock every administrator out of the organization.