Single Sign-On

Let your users sign in to Xelon HQ with their Microsoft (Entra ID) credentials, with permissions driven by Entra group membership.

Xelon HQ supports organization-level Single Sign-On (SSO) using the SAML 2.0 protocol. Xelon HQ acts as the Service Provider (SP) and Microsoft Entra ID (formerly Azure Active Directory) acts as the Identity Provider (IdP). SSO is configured per organization from the Microsoft Authentication card on the organization detail page.

Key characteristics

  • SAML 2.0 — not OAuth / OpenID Connect.
  • Just-in-time provisioning — a Xelon HQ user is created automatically on first successful login. There is no user import step.
  • Group-based permissions — access comes from Entra security-group membership, mapped to Xelon HQ permissions through Group → Permission Bundles. Membership is re-evaluated on every login.
  • Password login is blocked for every user on a verified SSO domain once SSO is enabled — except breaking-glass accounts listed under Password Login Exceptions.
  • SHA-256 or stronger signatures only. SHA-1 assertions are rejected.
Do not enable SSO before the configuration is complete

Turn on the Enable SSO toggle only after every required section is configured and at least one breaking-glass user exists. Enabling SSO with an incomplete or wrong configuration can lock every administrator out of the organization.