Single Sign-On (SSO) lets your team log in to CustomerSure through the identity provider they already use for work, such as Microsoft Entra ID, Okta or Google Workspace. Users start from the CustomerSure login page, enter their work email address and complete authentication with your identity provider.
We set up the connection with your IT team. Once it is working, your CustomerSure administrators can choose whether SSO is optional or required and whether new users should be created automatically on their first successful login.
CustomerSure connects to identity providers that support SAML or OpenID Connect (OIDC). Microsoft Entra ID SAML is the most common setup, but we will connect to anything reasonable such as Okta or Google Workspace.
To set up a connection, we will ask for:
Do not require SSO until at least one CustomerSure administrator has completed a successful end-to-end login.
Your identity provider handles the primary authentication. CustomerSure does not receive your identity provider password.
Once the connection has been tested, a CustomerSure administrator can open Company Settings → Security → Single Sign-On and switch on the SSO mandate.
When the mandate is enabled:
The mandate applies to every CustomerSure user in your organisation. Agree how your IT and CustomerSure administrators will respond to an identity provider outage before switching it on.
Just-In-Time provisioning (JIT) can create a CustomerSure account when an authorised person logs in successfully for the first time. This is optional and can be switched on or off by a CustomerSure administrator.
JIT only accepts email addresses from domains that CustomerSure has approved for your account. A new user is created as a Viewer who can only see feedback linked to themselves. A CustomerSure administrator can then grant access to other feedback, surveys, sites, regions or teams.
JIT copies the person’s first name, surname and email address from the identity provider when it creates the account.
If you need an employee reference or another identity provider attribute copied into CustomerSure, tell us during discovery. We can help set up any additional mappings.
Get in touch and we will work with your IT team to choose the right connection and get it tested.