<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE topic PUBLIC "-//OASIS//DTD DITA Topic//EN" "../dtd/topic.dtd">
<topic id="topic5472" xml:lang="en-us">
  <title>[RETIRED] Single sign-on (SSO)</title>
  <shortdesc>Set up Microsoft Office 365 single sign-on so users can access SafeSend with existing credentials and administrators can manage access.</shortdesc>
  <body>
    <draft-comment>Retired for WI 5590920</draft-comment>
    <p outputclass="openallaccordions">Show all hidden content.</p>
    <p>Single sign-on makes logging into SafeSend fast, easy, and secure. Users can sign in by selecting the <uicontrol>Continue with Office 365</uicontrol> button on the sign in page.</p>
    <note>Single sign-on is currently only available for Microsoft Office 365.</note>
    <p><uicontrol>Enable Single Sign-On In SafeSend</uicontrol> </p>
    <p>An administrator on the account must turn on single sign-on in SafeSend.</p>
    <ol>
      <li>Go to the <uicontrol>Product Settings</uicontrol>.</li>
      <li>Select <uicontrol>Security</uicontrol>.</li>
      <li>Select the <uicontrol>Gear</uicontrol> icon under the <uicontrol>Single Sign-On</uicontrol> section.</li>
      <li>Select one of the 3 options: <uicontrol>Azure Ad Group(s)</uicontrol>, <uicontrol>SSR Users List</uicontrol>, or <uicontrol>Azure</uicontrol> <uicontrol>Tenant ID</uicontrol>.</li>
      <li>Enter <uicontrol>Group ID</uicontrol> or <uicontrol>Tenant ID</uicontrol> if necessary.
        <note>Refer to the following for more information on user sign-in based on the selected setting.</note>
      </li>
      <li>Select <uicontrol>Add</uicontrol>.</li>
      <li>The <uicontrol>O365</uicontrol> switch button will be turned to <uicontrol>On</uicontrol>. </li>
    </ol>
    <p><uicontrol>Signing in</uicontrol> </p>
    <note>Depending on the Azure company settings, you may receive a permissions pop-up after the 1st sign-in to SafeSend.
      <ul>
        <li>Azure Administrator can mark the <uicontrol>Consent on behalf of your Organization</uicontrol> checkbox to let other users bypass this screen.</li>
      </ul>
    </note>
    <div outputclass="accordion">
      <p outputclass="accordionlabel">Azure Ad Groups </p>
      <div outputclass="accordioncontent">
        <p>When this option is used, users will be automatically created in SafeSend and will let them sign in using their Office 365 credentials.</p>
        <ul>
          <li>Approval is not required.</li>
          <li>Users automatically added will only have the Staff user group. </li>
        </ul>
        <p><uicontrol>Obtain Microsoft Office 365 Group ID</uicontrol> </p>
        <note>
          <ul>
            <li>A system administrator must create a group in Azure and add the ID to the Product Settings before registering and adding the enterprise application.</li>
            <li>If a user belongs to multiple AD Groups, they’ll need to approve access when signing in for the 1st time.</li>
          </ul>
        </note>
        <ol>
          <li>Sign in to the Azure Portal.</li>
          <li>Go to <uicontrol>Active Directory</uicontrol> to open the <uicontrol>Domain Overview</uicontrol> page.</li>
          <li>Select <uicontrol>Groups</uicontrol>.</li>
          <li>Enter the name of the group you are looking for in the <uicontrol>Search Groups</uicontrol> field.</li>
          <li>Copy the <uicontrol>Group ID (Object ID)</uicontrol> from the <uicontrol>Object ID</uicontrol> column.</li>
        </ol>
        <p><uicontrol>Register for the SafeSend Suite Enterprise Application</uicontrol> </p>
        <p>A system administrator will need to add SafeSend as an Enterprise Application before they’ll have access to add user groups.</p>
        <ol>
          <li>Search for <uicontrol>Enterprise applications</uicontrol> from the <uicontrol>Azure Portals Global Search</uicontrol> field.</li>
          <li>Once the application is opened, select <uicontrol>+ New Application</uicontrol>. This will take you to the Microsoft Entra Gallery.</li>
          <li>Search for <uicontrol>SafeSend Suite SSO</uicontrol> and select on the application to continue the registration.</li>
          <li>Select <uicontrol>Sign up for SafeSend Suite SSO</uicontrol> </li>
          <li>The SafeSend site will open, and here you will select <uicontrol>Continue with Office 365</uicontrol>.</li>
          <li>A consent screen will open. Select <uicontrol>Accept</uicontrol>.
            <ul>
              <li>Administrators can select <uicontrol>Consent on behalf of your organization</uicontrol>
                <ul>
                  <li>If this is not selected, the consent will only apply to the logged-in user.</li>
                  <li>All remaining users that sign in will have to <uicontrol>Accept</uicontrol> when they sign in using <uicontrol>Continue with Office 365</uicontrol>.</li>
                </ul>
              </li>
            </ul>
          </li>
        </ol>
        <p><uicontrol>Add Users/Groups to the Enterprise Application</uicontrol> </p>
        <note>A user group must be already created to complete the following steps.</note>
        <ol>
          <li>Go to <uicontrol>Enterprise applications</uicontrol>. </li>
          <li>Search for <uicontrol>SafeSend Returns</uicontrol>. </li>
          <li>Select <uicontrol>+Add User/Groups</uicontrol>.</li>
          <li>Select <uicontrol>None Selected</uicontrol> from left-hand side.</li>
          <li>Select the groups to add to SafeSend, then <uicontrol>Select</uicontrol>.</li>
          <li>The next screen will show all the groups selected. Select <uicontrol>Assign</uicontrol>.</li>
        </ol>
        <p>If you have any trouble accessing Azure Portal or obtaining your Group ID, contact <xref format="html" href="https://azure.microsoft.com/en-us/support/options/" scope="external">Microsoft® Azure Support.</xref> </p>
        <p>If you receive the following error, upgrade your Microsoft® subscription to a plan that includes Groups, or use the <uicontrol>User List</uicontrol> option in SafeSend: <uicontrol>Please add Azure Group ID(s) to enable O365</uicontrol>.</p>
      </div>
    </div>
    <div outputclass="accordion">
      <p outputclass="accordionlabel">User List </p>
      <div outputclass="accordioncontent">
        <p>The SSR user list lets existing users sign in using their Microsoft® Office 365 credentials.</p>
        <ul>
          <li>The user will need to appear in the Azure Tenants and SafeSend for a successful sign in.</li>
          <li>No approval is needed.</li>
        </ul>
      </div>
    </div>
    <div outputclass="accordion">
      <p outputclass="accordionlabel">Azure Tenant ID </p>
      <div outputclass="accordioncontent">
        <p>This option lets you add your Azure Tenant ID in which all users corresponding to that ID can sign in using their Office 365 credentials.</p>
        <ul>
          <li>If the user is already added as a user in SafeSend, no approval is needed for access.</li>
          <li>If the user is NOT already a user in SafeSend, approval is required for the user to access.</li>
        </ul>
        <p><uicontrol>Approve or Deny New Users</uicontrol> </p>
        <p>The approval (or denial) can be done via email or in SafeSend. This is a one-time approval.</p>
        <p><uicontrol>Email</uicontrol> </p>
        <ul>
          <li>The firm admin will receive an email that a new user is requesting access via Microsoft® Office 365.
            <ul>
              <li>They’ll have the ability to Approve or Deny those permissions from that email request.</li>
            </ul>
          </li>
        </ul>
        <p><uicontrol>SSR App</uicontrol> </p>
        <ol>
          <li>Go to <uicontrol>Account Management.</uicontrol> </li>
          <li>Select <uicontrol>User Permissions</uicontrol>. </li>
          <li>Select <uicontrol>Grant Access</uicontrol> or <uicontrol>Deny</uicontrol> for each user.</li>
        </ol>
      </div>
    </div>
    <p><uicontrol>Revoke SSO (Single Sign-On) Access</uicontrol> </p>
    <p>SSO can also be revoked after the user has been given access:</p>
    <ol>
      <li>Go to <uicontrol>User Management</uicontrol>. </li>
      <li>Find the <uicontrol>User</uicontrol> you want to revoke access to, then select the <uicontrol>Action(...)</uicontrol> menu.</li>
      <li>Select <uicontrol>Revoke Office 365</uicontrol>. </li>
      <li>You can choose to revoke access <uicontrol>Temporarily</uicontrol> or <uicontrol>Permanently</uicontrol> by selecting the respective option.
        <ul>
          <li><uicontrol>Temporarily</uicontrol>: The user will lose the ability to sign in via SSO but can request SSO access again. The system admin will have to admit them.</li>
          <li><uicontrol>Permanently</uicontrol>: The user will lose the ability to sign in via SSO but can't request access again. To reinstate SSO access, the system admin will have to edit the specific user in <uicontrol>User Management</uicontrol>.</li>
        </ul>
      </li>
      <li>Select <uicontrol>Apply Changes</uicontrol>.</li>
    </ol>
  </body>
</topic>