Single Sign-On (SSO) migration: What to expect
If you currently use SSO, review what changes, what stays the same, and how to prepare your organization for a smooth migration to the Thomson Reuters Account.
For general information about Federated SSO, supported standards, and how SSO works, refer to the Federated Single Sign-On article.
What changes for ONESOURCE SSO users
New entry point for sign-in
ONESOURCE sign-in will route through Thomson Reuters Account.
When a Thomson Reuters Account-compatible SSO connection is configured, users with your corporate email domain are automatically redirected to your Identity Provider (IdP) during sign-in. Automatic redirection occurs only after the new SSO connection is set up and turned on.
During rollout, some users may continue to use the existing SSO route temporarily while migrated users begin signing in through Thomson Reuters Account.
While the sign-in entry point changes, users will continue to authenticate through your organization's existing corporate Identity Provider (IdP).
Thomson Reuters configures and validates the SSO connection ahead of migration to ensure users can continue signing in without interruption.
What may impact your end users
If your SSO URL changes (for example, a new IdP-initiated link or a new entry point is required), your end users will need updated instructions. You may need to update bookmarks, portal tiles, or internal documentation.
If you change the MFA method or authenticator app or device in the IdP, users may be asked to re-enroll or complete MFA using a different method. This can create a direct impact on your users.
Email-based identity standardization
The Thomson Reuters Account uses email as the primary identifier for all users.
To support a smooth migration, user email addresses should be current, unique, and accessible.
As part of the migration, your SSO configuration may require updates to ensure that Thomson Reuters consistently identifies users using the correct email address.
Ensure your IdP sends the correct email-based identifier for each user, not aliases, or outdated values. This prevents sign-in issues and duplicate account scenarios.
What remains the same
Your Identity Provider (IdP)
Your organization continues to own and fully manage SSO within your Identity Provider (for example, Azure AD, Okta, Ping). This migration doesn’t require your organization to replace its IdP.
How users authenticate
Users will continue to:
- Sign in with their corporate credentials.
- Follow your organization's MFA requirements.
- Follow your organization's existing security policies.
Thomson Reuters Account changes where authentication is routed, not how authentication is performed.
User access, roles, and permissions
This migration affects authentication only. There is no change to:
- User roles
- Permissions
- Product access
- Tenant entitlements
ONESOURCE continues to manage authorization.
Recommended preparation
Before migration, we recommend that your team:
- Review your current SSO configuration and ownership.
- Confirm technical and business contacts.
- Verify the accuracy of all user email addresses.
- Identify and update your service and bot accounts by going toAdministration, thenUser Details.
Migration stages
A typical migration includes the following stages.
Stage 1: Discovery and planning
Thomson Reuters and your team review:
- Your current SSO configuration
- Impacted users or tenants
- Domain information
- Technical dependencies
- Migration timing
Stage 2: Configuration and validation
Thomson Reuters and your IT team:
- Confirm the SSO configuration approach.
- Configure or update the Thomson Reuters Account SSO as needed.
- Validate routing and authentication behavior.
- Confirm any required sign in instruction changes.
Stage 3: Testing
Thomson Reuters and your team complete joint testing to confirm the updated sign-in experience works as expected. Typical validation steps include:
- Flag a small number of test users by going to .
- Have each user complete registration and the upgrade process.
- After the upgrade, have each user sign in through the Thomson Reuters Account sign-in page.
- The user enters their email address and confirms redirection to your organization's IdP.
- Confirm successful return to ONESOURCE.
- Confirm the user has the expected access after authentication.
Stage 4: Go-live
Thomson Reuters enables the new SSO experience according to the agreed migration plan. All users are upgraded and begin signing in through Thomson Reuters Account.
Stage 5: Post-go-live support
After go-live, Thomson Reuters and your team monitor:
- Sign-in success
- Support issues
- Remaining users or exceptions
- Readiness to retire prior sign in paths where necessary