SurePrep Single Sign-On (SSO) integration
SurePrep Single Sign-On (SSO) integration lets a firm implement its identity policy to authenticate a user's credentials. SSO also gives firm users the convenience of logging in directly from a firm's sign in portal instead of SurePrep FileRoom. Once a user signs in to your firm, you can use the Security Assertion Markup Language (SAML) 2.0 protocol to pass authorization credentials to SurePrep.
note
SAML implements a secure method of passing user authentications and authorizations between your firm and SurePrep. SAML also enables SSO, letting the user sign in once, and using those same credentials to sign in to other service providers (that is, SurePrep).
Prerequisites
To initiate SSO integration, you must first complete a worksheet provided by SurePrep.
Provide the following details in the worksheet:
- Entity ID
- Signing Certificate
- SAML Subject
- Attribute list
- User access URL
Setup
- Provide SurePrep Support with the filled worksheet.
- SurePrep will complete the configuration (that is, Certificates, Entity ID, Registration), then enableMixed Modeon the domain. Mixed mode lets users sign in using either the FileRoom sign in or through their firm's portal using SSO.
- (Recommended) Once you turn on mixed mode, SurePrep will enable test users provided by you for mixed mode.
- Test users can sign in using SSO or SurePrep credentials.
- If test users verify their sign-in successfully using SSO, SurePrep will let all users use SSO mixed mode.
- Once a firm verifies they have successfully logged in using SSO, they can then go on to SSO only mode. If SSO only mode is turned on, users can only sign in to SurePrep from your firm's sign in portal using SSO credentials.noteOnly users in the Firm System Administrators permission group can sign in using SSO as well as SurePrep credentials in SSO Only mode.
- Firm users can then successfully sign in with SSO.
note
Clients using Azure to authenticate
: If you are having difficulty using SSO after setup, check your settings in Azure to ensure that the Sign on URL
field is blank. Additional Links
- Enabling SSO for your firm (Current article)
- Signing in to FileRoom through SSO
- Single Sign-On (SSO) user management