How to enable single sign-on
Enabling single sign-on allows your staff to access the Thomas platform using their existing work accounts.
Supported configurations
Entra accounts with OIDC
-
Sign in to the Entra admin centre. You must use an account with permission to create app registrations.
-
Create a new app registration by following the Microsoft guidance:
https://learn.microsoft.com/en-us/entra/identity-platform/quickstart-register-app -
Generate a Client ID and Client Secret.
Okta accounts with OIDC
-
Create a new OIDC (OpenID) app integration.
-
Follow the Okta guidance:
https://help.okta.com/en-us/content/topics/apps/apps_app_integration_wizard_oidc.htm
Other identity providers
If you use a different identity provider, please raise a support request here, and we will do our best to accomodate you.
Raise a connection request
Once your app has been created, raise a support request here and provide the following details:
-
Tenant ID
-
Client ID
-
Client Secret
-
List of email domains that will use single sign-on
Next steps
After receiving your request:
-
Thomas will complete the configuration in the background.
-
A callback URL will be provided. This must be added to the app registration or integration created earlier.
-
A date and time will be arranged to enable single sign-on and complete testing.