← Back to support

Logging in with your own organisation account (SSO)

Single sign-on (SSO) lets your employees sign in to the learning platform with the account they already have from your organisation. They don't need a separate password, and you manage access centrally. The platform offers two ways:

  • Sign in with Microsoft or Google, the quickest option. You set nothing up; employees click the button on the sign-in page and confirm with their own account.
  • SAML 2.0 with your own identity provider (Microsoft Entra ID or Google Workspace), more work to set up but fully managed by your organisation.

This guide first covers a few settings that apply to both, then each method step by step.

Before you start: new users and email domains

In your organisation's admin, under Access and security, the Single sign-on: new users settings decide what happens when someone signs in via SSO while no account exists yet. This choice applies to both methods.

  • Unknown user on SSO sign-in: choose whether the account is created automatically on first sign-in, or whether only existing accounts may sign in. On automatic creation the new user gets the default role and is linked to your organisation. The licence is respected: if the organisation is full, no account is created and the user sees a message.
  • Email domains of this organisation: only needed for automatic creation via Microsoft or Google. That sign-in runs through one shared connection that carries no organisation itself, so the email domain determines which organisation a new user belongs to. If more than one organisation claims the same domain, nothing is created. This field is not needed for SAML.

Two-step verification (MFA): this applies to accounts that sign in with a password. Anyone signing in via Microsoft or Google passes through the security of their own organisation account and does not need this setting.

Method 1: Sign in with Microsoft or Google

The fastest route. You don't set up your own identity provider; the platform uses a connection managed by 2LRN4. There are no certificates or URLs to exchange.

  1. Under Access and security (see above), enter your organisation's email domain and choose what should happen for an unknown user.
  2. Make sure the email addresses of your employees in the platform match their Microsoft or Google account. They are recognised on that.
  3. Your employees go to the sign-in page and choose Sign in with Microsoft or Sign in with Google. They confirm with their own organisation account and enter the platform. If the account does not exist yet and automatic creation is on, it is created right away.

Method 2: SAML 2.0 with your own identity provider

With this route you set up a connection with the platform in your own identity provider. Steps 1, 3 and 4 are the same for every provider; only step 2 differs. We describe Microsoft Entra ID and Google Workspace. Allow about twenty minutes.

Step 1: create an SSO connection in the platform

  1. In the admin, go to SSO and click Create.
  2. Keep this screen open; you'll need the platform's details in your identity provider.

The platform uses these fixed addresses (the service provider details):

  • Entity ID / metadata: https://portal.2lrn4.com/saml2/metadata
  • Reply URL (ACS): https://portal.2lrn4.com/saml2/acs
  • Logout URL (SLS): https://portal.2lrn4.com/saml2/sls

Step 2A: Microsoft Entra ID

  1. In the Microsoft Entra admin center, go to Enterprise applications, then New application and Create your own application. Give it a recognisable name, for example "2LRN4 learning platform".
  2. Choose Single sign-on and then SAML.
  3. Under the basic SAML configuration, enter the details from step 1: Identifier (Entity ID) = https://portal.2lrn4.com/saml2/metadata, Reply URL = https://portal.2lrn4.com/saml2/acs, Logout URL = https://portal.2lrn4.com/saml2/sls.
  4. Under Attributes & Claims, make sure the email address is sent as the unique user id (NameID), together with the first and last name.
  5. Assign the application to the users or groups that may have access.

Step 2B: Google Workspace

  1. In the Google Admin console (admin.google.com), go to Apps, then Web and mobile apps, and choose Add app and Add custom SAML app. Give the app a recognisable name.
  2. Google shows its own details: an SSO URL, an Entity ID and a certificate. Download the certificate and keep these three at hand for step 3.
  3. Under Service provider details, enter the details from step 1: ACS URL = https://portal.2lrn4.com/saml2/acs, Entity ID = https://portal.2lrn4.com/saml2/metadata, and as Name ID the primary email address (EMAIL format).
  4. Under Attributes, map the email address, first name and last name.
  5. Turn the app on for the right organisational units or for everyone.

Step 3: put your provider's details into the platform

In the SSO connection (the screen from step 1), enter the details your provider gave you:

  • Entity id: your provider's Entity ID. In Entra ID the "Microsoft Entra Identifier", in Google the "Entity ID".
  • Single Signon Service: the sign-in URL. In Entra ID the "Login URL", in Google the "SSO URL".
  • Single Logout Service: the logout URL. Entra ID provides one; Google Workspace does not, so leave this field empty for Google.
  • X.509 certificate: the signing certificate you download from your provider, in Base64 form.

Click Save.

Step 4: test

The list of SSO connections shows a sign-in link per connection, of the form https://portal.2lrn4.com/saml2/login?entityId=…. Open it in a private window and sign in with an organisation account you gave access in step 2. If you land in the learning platform, the connection works. Then share that sign-in link with your employees, or have it used as the sign-in button for your organisation.

Frequently asked questions

An employee doesn't exist in the platform yet. What then?

You set this under Access and security: if "Unknown user on SSO sign-in" is set to create automatically, the employee gets an account with the default role on first sign-in. For the Microsoft/Google sign-in the email domain of your organisation must be filled in. Linking happens on the email address, so it must match the account at your provider.

Sign-in fails. Where do I look first?

For SAML, usually one of three things is off: the reply URL at your provider differs from https://portal.2lrn4.com/saml2/acs, the certificate in the platform has expired or is not the right one, or the email address is not sent as NameID. Go through steps 2 and 3 again. For the Microsoft/Google sign-in: check that the email address matches and that the domain is filled in. If you're stuck, our support will help you further.

Stuck?

Ask a question or book a short demo. We'll help you move forward.