Skip to content
HELP CENTER/ADMIN & ACCOUNT SETUP/SETTING UP SINGLE SIGN-ONUPDATED 15 AUG 2026

Setting up single sign-on

Connect your identity provider so access follows your existing joiners and leavers process.

Hendl Support · Updated 15 Aug 2026
On this page

SSO is available on plans that include it. Check Settings → Billing or ask your account contact.

Why it is worth doing early

Not password hygiene — offboarding. Without SSO, removing someone's access is a separate task in a separate system that somebody has to remember on their last day. With it, disabling their directory account disables Hendl.

What you need

  • Administrator in Hendl and in your identity provider.
  • SAML 2.0 or OIDC. Entra ID, Okta and Google Workspace are all straightforward.
  • A test account that is not yours. Locking yourself out of the tenant you are configuring is a genuinely bad afternoon.

Configure it

  1. Settings → Authentication → Single sign-on.
  2. Copy the ACS URL and entity ID into a new application in your provider.
  3. Map email as the identifier. Optionally map a group claim to Hendl roles.
  4. Paste the provider's metadata URL or certificate back into Hendl.
  5. Test with the test account before enforcing. The test button signs in without changing anything.
  6. Enforce.

Break-glass access

One Administrator account keeps password access after enforcement. This is deliberate: an identity provider outage should not lock you out of your own casework. That account should have a long unique password, be held in your password manager, and be reviewed whenever you review Administrators.

Group mapping

If you map groups to roles, the mapping runs on every sign-in and overrides roles set in Hendl. Someone moved between groups in your directory changes role the next time they sign in, with the change recorded in the audit log.

Did this answer your question?
More in Admin & account setup