How do I set up and use Organization SSO?

Modified on Mon, 31 Aug at 11:14 AM

The possibility to connect via Single Sign-On (SSO) depends on the configuration of the Data Exchange Solution to which you are connecting. To find out more, contact the Orchestrator team.

Organization SSO allows your organization to connect your own identity provider (Google Workspace or Microsoft Entra ID) to the Data Exchange Solution. Your team members can then log in directly with your company’s credentials and automatically join your organization, with no manual account creation required.


What is Organization SSO?

Unlike standard SSO (Google or Microsoft, open to everyone), Organization SSO is specific to your company: as the administrator, you register your own identity provider (IdP) with Google or Microsoft, and then link it to your organization on the Participant Portal.

Your organization members then need to know only one piece of information to log in: your organization’s unique identifier. This identifier automatically redirects them to your SSO login page, where they authenticate using their usual work credentials and then join your organization on the Participant Portal.

Main benefits:

  • centralized access management within your own corporate authentication system,
  • elimination of dedicated Participant Portal passwords for your organization,
  • automatic and secure assignment of your colleagues to the correct organization.

Configuring an identity provider (IdP) for your organization

  1. Go to My Organization > General Settings, then open the section dedicated to Organization SSO.
  2. Click Add SSO.
  3. Choose the identity provider: Google Workspace or Microsoft Entra ID.
    If your Data Exchange Solution access plan only includes one identity provider, it is automatically selected and cannot be changed. To activate a second identity provider, contact the Orchestrator team.
  4. Enter your application’s information, as declared in the Google or Microsoft admin console:
FieldDescriptionRequired
Configuration nameInternal name used to identify the configuration (2 to 100 characters, no special characters)Yes
Client IDClient identifier of the application declared with your providerYes
Client secretSecret associated with the applicationYes
Tenant IDIdentifier of your Microsoft tenantYes, for Microsoft only
  1. Save the configuration. The Data Exchange Solution automatically verifies the validity of your credentials with the identity provider before confirming the save.
You can declare several SSO configurations for your organization, for example if multiple applications or providers are used internally. Each configuration must have a unique name within your organization.

Setting your organization’s unique login identifier

Once your identity provider is configured, enter your organization’s unique identifier on the SSO configuration page. This is the identifier your organization members will need to enter to access your SSO login page.

This identifier must be unique across the entire Participant Portal: upon saving, the system checks that it is not already used by another organization. In case of a duplicate, an error message is displayed and you must choose a different one.

Share this identifier with your organization members, as they will need it to log in via your organization’s SSO.

Editing, disabling, or deleting an SSO configuration

From your organization’s list of SSO configurations, you can at any time:

  • edit the configuration name, Client ID, Client secret, or Tenant ID,
    If you do not enter a new Client secret, the one already saved is kept.
  • change the identity provider associated with an existing configuration (Google or Microsoft),
  • disable a configuration, without losing the saved settings,
  • delete a configuration, only if it has been previously disabled.

For more information, see the articles:

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article