← Back to support

Logging in with your own organisation account (SSO)

With single sign-on, your employees log in to 2LRN4 with the account they already have, usually their Microsoft or Google work account. That way they do not have to remember a separate password for 2LRN4, and your organisation stays in control: anyone who leaves and no longer has an organisation account can no longer get into 2LRN4 either.

Two approaches

1. The Microsoft or Google button on the login page. This is the simplest form and requires no setup on your side. Each user has a setting for how they log in (with a password, with Microsoft or with Google); you change that on the user profile or in bulk from the user overview. If you use automatic user synchronisation with Microsoft Entra or Google Workspace, this is set correctly straight away.

2. A SAML connection with your own Identity Provider. For organisations that manage access centrally, for example with Entra ID (formerly Azure AD), ADFS or Okta. You will find this in the administration under Saml2 for your organisation. There you enter four details of your Identity Provider, which your identity administrator supplies:

  • the entity ID of the Identity Provider;
  • the login URL (single sign-on service);
  • the logout URL (single logout service);
  • the X.509 certificate.

Once you have saved, the overview shows the login URL of your organisation. You can share it internally, for example as a tile on the intranet. We send you the details your identity administrator needs from us on request; we are also happy to look over your shoulder while you set it up and test it.

What happens with an unknown user?

If someone logs in via SSO while no 2LRN4 account exists yet, a setting on your organisation determines what happens. You will find it on the organisation form under Single sign-on — new users, at the Unknown user at SSO login list. There are three possibilities:

  • Follow the platform default (the starting position). You do not make a choice yourself; the organisation follows whatever has been set platform-wide. Handy as long as you have not consciously decided about it, but it is better to fix the choice, so that you are not taken by surprise if the platform default changes.
  • Account must already exist (recommended). Only people who are already in 2LRN4 can log in. New employees arrive through user synchronisation or through an import, and you keep control over who takes up a place.
  • Create the account automatically at first login. Anyone logging in for the first time immediately gets an account with the default role, linked to your organisation. The licence is watched over in the process: if your organisation is full, no account is created and the user sees a clear message on the login page.

If you choose automatic creation in combination with the Microsoft or Google button, also fill in the Email domains of this organisation field (several are allowed, separated by commas, for example customername.com, customername.co.uk). Those buttons work with one shared connection for all customers, so the email domain determines which organisation a new user belongs to. If more than one organisation claims the same domain, nothing is created; that is deliberate, because the platform then cannot establish where the user belongs. With a SAML connection that field is not needed, because that connection already belongs to your organisation.

For most organisations we recommend combining user synchronisation with Account must already exist. Synchronisation creates accounts with the right department and language, and switches them off as soon as someone leaves. Automatic creation at login is handy if you do not use synchronisation, but the user then starts without a department; in that case, check the No department filter in the user overview regularly.

If you cannot find this block on the organisation form, your account lacks the right to manage configuration. The setting is only visible to the administrator role; ask a colleague who has that role, or your contact at 2LRN4.

Good to know

  • Two-step verification is handled by your Identity Provider. Anyone logging in via SSO goes through the security of their own organisation account, including MFA if you have that switched on. The MFA setting in 2LRN4 itself is meant for accounts that log in with a password.
  • Forgotten password does not apply here. An SSO account has no 2LRN4 password, and the forgotten-password function deliberately does nothing with it. If an employee gets stuck, the solution lies with the organisation account itself.
  • A failed SSO login gives a message. The user comes back to the login page with a text that says what is going on, for example that the account does not exist yet or that the licence is full.
  • Try it with a small group first. Get the connection ready, test with a few colleagues from different departments, and only roll SSO out widely after that. We are happy to think along about the order.
Stuck?

Ask a question or book a short demo. We'll help you move forward.