How to enable single sign-on
Enabling single sign-on allows your staff to access the Thomas platform using their existing work accounts.
Thomas currently supports single sign-on using:
- Microsoft Entra with OIDC
- Okta with OIDC
- SAML, reviewed on a case-by-case basis
- Other identity providers, reviewed on request
Before raising a request, your technical team will need to create the relevant application or integration in your identity provider and gather the required details.
Supported configurations
Microsoft Entra with OIDC
-
Sign in to the Entra admin centre. You must use an account with permission to create app registrations.
-
Create a new app registration by following the Microsoft guidance:
https://learn.microsoft.com/en-us/entra/identity-platform/quickstart-register-app -
Generate a Client ID and Client Secret.
- Make a note of the following details:
Tenant ID
Client ID
Client secret
Email domain or domains that should use SSO - Raise a support request with Thomas and include the details above.
What Thomas will do next
After receiving the required details, Thomas will complete the configuration on our side.
Once the Thomas configuration is complete, we will provide a callback URL. Your technical team must add this callback URL to the app registration created in Microsoft Entra.
A date and time will then be arranged to enable single sign-on and complete testing.
Okta accounts with OIDC
Use this option if your organisation uses Okta and wants to connect to Thomas using OIDC.
-
Create a new OIDC (OpenID) app integration.
-
Follow the Okta guidance:
https://help.okta.com/en-us/content/topics/apps/apps_app_integration_wizard_oidc.htm - Generate or collect the required OIDC details.
- Make a note of the following:
Okta domain or issuer URL
Client ID
Clientsecret
Email domain or domains that use SSO - Raise a support request with Thomas and include the details above
What Thomas will do next
After receiving the required details, Thomas will complete the configuration on our side. Once the Thomas configuration is complete, we will provide a callback URL. Your technical team must add this callback URL to the Okta app integration created earlier. A date and time will then be arranged to enable single sign-on and complete testing.
SAML
Use this option if your organisation needs to connect to Thomas using SAML.
SAML setup is currently reviewed on a case-by-case basis. To avoid delays, please make sure your technical team can provide the required SAML information listed below.
- Confirm which identity provider you use, for example Microsoft Entra, Okta, or another SAML provider.
- Create a new SAML application for Thomas in your identity provider.
- Thomas will provide the required Service Provider details once your request has been reviewed.
These may include:- Service Provider Entity ID
- Reply URL / Assertion Consumer Service URL
- Add the Thomas Service Provider details to your SAML application when provided.
- Configure the required user identifier and claims.
In most cases, the user identifier should be based on the user’s email address. - Assign the relevant users or groups to the Thomas SAML application.
- Provide Thomas with your SAML metadata.
Information Thomas needs for SAML
Please provide:
- Identity provider name
- App-specific metadata URL from your identity provider
- Email domain or domains that should use single sign-on
- Confirmation that the relevant users or groups have been assigned to the Thomas application
- Test user details, where possible
For Microsoft Entra, the metadata URL should be copied from the SAML page for the Enterprise Application created for Thomas.
You can usually find this in Microsoft Entra here:
Enterprise Applications > the application created for Thomas SSO > Single sign-on > SAML Certificates > App Federation Metadata Url
Please make sure this is the App Federation Metadata Url for the Thomas application, not the general tenant-level federation metadata URL.
What Thomas will do next
After receiving the required SAML details, Thomas will review the configuration and complete the setup on our side. A date and time will then be arranged to enable single sign-on and complete testing.
Other identity providers
If you use a different identity provider, please raise a support request and tell us:
- Which identity provider you use
- Whether you want to use OIDC or SAML
- The email domain or domains that should use single sign-on
- Any technical documentation your identity provider provides for OIDC or SAML integrations
We will review the request and confirm whether we can accommodate the setup.
Raise a connection request
Once your application or integration has been created in your identity provider, raise a support request and provide the relevant details.
For Microsoft Entra OIDC
Please provide:
- Tenant ID
- Client ID
- Client Secret
- Email domain or domains that should use single sign-on
For Okta OIDC
Please provide:
- Okta domain or issuer URL
- Client ID
- Client Secret
- Email domain or domains that should use single sign-on
For SAML
Please provide:
- Identity provider name
- App-specific metadata URL
- Email domain or domains that should use single sign-on
- Confirmation that users or groups have been assigned to the Thomas SAML application
- Test user details, where possible
Next steps
After receiving your request:
- Thomas will review the information provided.
- Thomas will complete the configuration on our side.
- For OIDC integrations, Thomas will provide a callback URL. This must be added to the app registration or integration created earlier.
- For SAML integrations, Thomas will provide any required Service Provider details that your technical team must add to your SAML application.
- A date and time will be arranged to enable single sign-on and complete testing.
Testing
Before testing, please make sure:
- The Thomas application has been created in your identity provider
- The correct users or groups have been assigned to the application
- The correct email domain or domains have been provided to Thomas
- The relevant users are using their work email address to sign in
- Your technical team is available to check identity provider logs if testing fails
If testing is unsuccessful, Thomas may ask for screenshots, error messages, identity provider sign-in logs, or a temporary test account, depending on the issue.
Multi-factor authentication
If your organisation uses multi-factor authentication, this is normally configured and managed within your own identity provider, such as Microsoft Entra or Okta.
Thomas configures the single sign-on connection, while your identity provider handles the user authentication process, including any MFA requirements, before returning the user to Thomas.