Single Sign-On (SSO) lets your team log in to CustomerSure through the identity provider they already use for work, such as Microsoft Entra ID, Okta or Google Workspace. Users start from the CustomerSure login page, enter their work email address and complete authentication with your identity provider.

We set up the connection with your IT team. Once it is working, your CustomerSure administrators can choose whether SSO is optional or required and whether new users should be created automatically on their first successful login.

What CustomerSure supports

CustomerSure connects to identity providers that support SAML or OpenID Connect (OIDC). Microsoft Entra ID SAML is the most common setup, but we will connect to anything reasonable such as Okta or Google Workspace.

What we need from your IT team

To set up a connection, we will ask for:

How setup works

  1. Contact us and tell us which identity provider you use.
  2. We create a dedicated SSO connection and send your IT contact the values and provider-specific instructions they need.
  3. Your IT team creates the CustomerSure enterprise application, adds the connection values and assigns the test users.
  4. Your IT team sends us the identity provider metadata or other required connection details.
  5. We complete the connection and test it with you.
  6. A CustomerSure administrator chooses whether to enable automatic user creation and whether to require SSO for everyone.

Do not require SSO until at least one CustomerSure administrator has completed a successful end-to-end login.

How users log in

  1. Go to the CustomerSure login page and choose Login with SSO.
  2. Enter your work email address.
  3. CustomerSure sends you to your organisation’s identity provider.
  4. Complete your organisation’s normal sign-in process.
  5. If your CustomerSure account also requires multi-factor authentication, complete that check before entering CustomerSure.

Your identity provider handles the primary authentication. CustomerSure does not receive your identity provider password.

Require SSO for everyone

Once the connection has been tested, a CustomerSure administrator can open Company Settings → Security → Single Sign-On and switch on the SSO mandate.

When the mandate is enabled:

The mandate applies to every CustomerSure user in your organisation. Agree how your IT and CustomerSure administrators will respond to an identity provider outage before switching it on.

Create new users on first login

Just-In-Time provisioning (JIT) can create a CustomerSure account when an authorised person logs in successfully for the first time. This is optional and can be switched on or off by a CustomerSure administrator.

JIT only accepts email addresses from domains that CustomerSure has approved for your account. A new user is created as a Viewer who can only see feedback linked to themselves. A CustomerSure administrator can then grant access to other feedback, surveys, sites, regions or teams.

JIT copies the person’s first name, surname and email address from the identity provider when it creates the account.

If you need an employee reference or another identity provider attribute copied into CustomerSure, tell us during discovery. We can help set up any additional mappings.

Security details for your IT team

Need a hand

Get in touch and we will work with your IT team to choose the right connection and get it tested.

You’re in good company

Beyond Housing
Philips
Barchester
Covéa
Ingenico
Connect Housing
Bristol Water

Recognised by

ICS Awards Finalist 2025
Housing Innovation Awards Finalist 2025
ICS Awards Finalist 2026
Housing Innovation Awards Finalist 2025