All pages
Powered by GitBook
1 of 3

Loading...

Loading...

Loading...

Logging in with SSO

Introduction

Unifize supports Single Sign-On (SSO), allowing you to log in with your existing company credentials β€” such as those you use for Microsoft 365, Google Workspace, or another identity provider. This feature replaces the need for a separate Unifize password and allows seamless access to the platform.

If your organisation has SSO enabled, you will be automatically routed through your company’s login page after entering your work email address. If your organisation has configured more than one SSO connection, Unifize will detect your email domain and route you to the correct login portal automatically. This applies to both the web platform and the mobile app.


Why SSO Is Useful

SSO enhances the login experience by integrating with your organisation’s existing authentication system. Here’s why it matters:

  • Secure by default: Your credentials never pass through Unifize. Authentication is handled directly by your company’s identity provider.

  • Simplifies access: No need to create or remember a separate password for Unifize.

  • IT-aligned: Helps organisations manage access centrally using existing systems like Azure AD or Google Workspace.

  • Supports MFA (Multi-Factor Authentication): If your company uses 2FA, SSO supports that too β€” providing added security.


You can use SSO to log into Unifize if:

  • Your organisation has enabled SSO in their Org Settings

  • Your email domain (e.g., @yourcompany.com) has been configured for SSO

  • You have been added as a user in your company’s identity provider system (e.g., Azure AD)

If you’re not sure whether your company uses SSO, ask your IT administrator or Unifize workspace admin.


  1. Open your browser and go to https://app.unifize.com

  2. Enter your work email address

  3. Unifize checks if your domain is SSO-enabled:

  4. If yes, you are redirected to your company’s login portal

  1. Open the Unifize app on your phone or tablet

  2. Enter your work email address

  3. You’ll be redirected to your company’s login page within the app

  4. Complete your usual login flow and MFA (if applicable)


In Unifize, some workflows require digital signature confirmation during approvals.

Because your password is managed outside Unifize when using SSO, you can’t re-enter a password to validate signatures. Instead:

  • You’ll receive a One-Time Passcode (OTP) to your registered email

  • The OTP is valid for 2 minutes

  • Enter the 6-digit code to confirm your signature

This ensures your approvals remain secure and traceable even when using SSO.


If no, you’ll see the traditional password field (for standard users)

  • Log in using your corporate credentials (email + password)

  • Complete any required MFA (multi-factor authentication) steps

  • You’ll be logged into Unifize and redirected to your workspace

  • Once authenticated, you’ll return to the app β€” logged in and ready to go

    ℹ️ Even if it’s your first time using Unifize, you don’t need to create a new password β€” SSO will handle the login.

    ℹ️ Mobile login flow is nearly identical to the web experience, adapted for mobile screens.

    Issue

    What to Try

    Not redirected to your company login

    Make sure your email domain is registered for SSO. Ask your admin to confirm the domain is configured in Org Settings β†’ SSO.

    See password field instead of SSO login

    Clear browser cache and retry, or confirm with your admin that your domain is mapped to an SSO tenant.

    Didn’t receive OTP

    Who Can Use SSO

    How to Log In with SSO

    On Desktop (Browser)

    On Mobile (iOS / Android)

    Digital Signatures and OTP (for SSO Users)

    Troubleshooting Tips

    Check your spam/junk folder, or request a resend. Confirm your email in Unifize matches your work email exactly.

    Login loop or error from IdP

    Make sure your browser or app allows third-party cookies/redirects.

    Mobile login stalls after IdP redirect

    Force-close and reopen the Unifize app, and update to the latest version.

    Redirected to the wrong company login page

    Your email domain may be mapped to the wrong SSO tenant. Contact your admin to review domain assignments in Org Settings β†’ SSO.

    SSO

    Feature ID: FU-1051

    Document Version: 3.0

    Date: 24-03-2026

    1. Introduction

    Unifize supports Single Sign-On (SSO) integration using the SAML 2.0 protocol. This allows users to authenticate with existing identity providers (IdPs) such as Microsoft Entra ID (formerly Azure AD), Google Workspace, or other SAML-compatible systems.

    It has full SSO support on desktop and mobile browser. Approvals are done via OTP-based digital signature. The authentication method is admin-configured per org. Users do not get to choose between SSO or password-based login.


    2. User Experience

    A. Desktop Login Flow

    1. User navigates to their Unifize portal

    2. Enters your email address

    3. If the domain has SSO configured:

      1. User is redirected to the corresponding IdP login

      2. Completes password entry and 2FA if required

      3. Redirects to Unifize as logged in user

    Note: The login screen may still display the "Sign Up Now!" prompt. However, SSO-configured domains will bypass this once the email is validated.

    1. User opens the Unifize mobile app

    2. Enters your email address

    3. If SSO is configured for the domain:

      1. User is redirected to the corresponding IdP login

    1. Open

    2. Enter your email address

    3. If your domain is SSO-enabled you'll be redirected to the same enterprise IdP login as the Web App.

    4. After authentication, redirected back to PWA.The PWA supports full SSO-based login and authorization flow identical to the Web App.


    SSO users can do 2FA for authorising their digital signature using email-based OTP flow:

    • Upon initiating a digital signature, the user receives a 6-digit OTP at their registered email

    • The OTP is valid for 2 minutes

    • Once entered, the β€œConfirm and Sign” button becomes active


    Note: Only org admin can set up SSO configuration. Please reach out to your admin for the following steps:

    1. Configure Azure Entra Id following the .

      In Azure, configure the following using values from Unifize (Org Settings β†’ SSO):

      1. Entity ID : Service Provider Entity ID from Unifize

      2. Reply URL(s):

    1. Go to Users and Groups in the created Enterprise Application

    2. Add relevant users to grant them access to Unifize

    3. Ensure the users' email domains match the configured domain


    • Only Org Admins can access and configure SSO settings

    • Users are automatically routed to SSO based on their email domain

    • For SSO access, users must:

      • Be added to the Unifize app group in the IdP


    Completes password entry and 2FA if required

  • Redirects to Unifize mobile app as logged in user

  • https://app.unifize.com/__/auth/handler
  • Add additional Reply URL for PWA: https://pwa.unifize.com/__/auth/handler

  • Sign-on URL : Org SSO URL from Unifize

  • Configure Unifize SSO Settings Go to Org Settings β†’ SSO in Unifize

    1. Choose Domain from the drop down. In case the domain is not listed, please reach out to your Unifize account manager.

    2. Fill the following values from Azure to unifize

      1. Entity ID : Microsoft Entra Identifier on Azure

      2. SSO URL : Login URL on Azure

      3. Certificate :

        • Download the "Base64 certificate" from Azure.

        • Copy paste the content of the file in the text area on Unifize.

  • Have an email address matching the configured domain

    B. Mobile App Login Flow

    C. PWA Login Flow (New)

    3. Approvals via OTP for SSO Users

    4. SSO Configuration & Setup

    2. Save the configuration

    3: Assign Users in IdP

    5. Permissions & Roles

    https://pwa.unifize.com
    Microsoft documentation
    πŸ–‹οΈEdit this page

    SSO using SAML

    Overview

    This guide walks Unifize workspace admins through setting up Single Sign-On (SSO) using SAML 2.0. When SSO is enabled, users in your org are authenticated through your company's identity provider (IdP)β€”such as Microsoft Entra ID, Okta, or Google Workspaceβ€”rather than with a Unifize password.

    You can configure one or more SSO tenants under a single org. This is useful when your users are spread across multiple IdP tenants (for example, separate Microsoft Entra ID directories for different subsidiaries). Each tenant is mapped to specific email domains, so users are always routed to the right login portal.

    Before You Begin

    Make sure you have the following ready before opening the SSO configuration page:

    • Access to your IdP admin console (e.g., Microsoft Entra ID, Okta, Google Workspace)

    • The email domain(s) you want to route through SSO (e.g., yourcompany.com)

    • Permission to create an enterprise application in your IdP

    • Unifize workspace admin role

    1. Log in to Unifize as a workspace admin.

    2. Navigate to Org Settings β†’ SSO.

    3. Click Add Tenant to begin configuring your first (or additional) SSO tenant.

    Before filling in your IdP details, copy the following values from the Unifize SSO configuration panel. You will need to enter these into your IdP's enterprise application setup.

    In your identity provider's admin console, create or open the enterprise application you will use for Unifize SSO, and enter the Unifize values from Step 2. The specific steps vary by IdP:

    1. Go to Microsoft Entra ID β†’ Enterprise applications β†’ New application.

    2. Select Create your own application and choose Integrate any other application you don't find in the gallery.

    3. Under Single sign-on, choose SAML.

    4. In Basic SAML Configuration, enter:

    • Identifier (Entity ID): paste the Identifier value from Unifize

    • Reply URL (ACS URL): paste the Reply URL from Unifize

    • Sign on URL: paste the Sign on URL from Unifize

    1. Save the configuration.

    2. Download the Certificate (Base64) from the SAML Signing Certificate section.

    3. Copy the Microsoft Entra Identifier (Entity ID) and Login URL from the Set up section.

    1. Go to Applications β†’ Create App Integration β†’ SAML 2.0.

    2. In the SAML Settings step, enter:

    • Single sign-on URL: paste the Reply URL from Unifize

    • Audience URI (SP Entity ID): paste the Identifier from Unifize

    1. Complete setup and go to the Sign On tab.

    2. Download the Signing Certificate and copy the Identity Provider Entity ID and Login URL.

    1. Go to Admin Console β†’ Apps β†’ Web and mobile apps β†’ Add app β†’ Add custom SAML app.

    2. Copy the SSO URL and Certificate from the Google IdP details pageβ€”you will need these in Step 4.

    3. In the Service Provider Details step, enter:

    • ACS URL: paste the Reply URL from Unifize

    • Entity ID: paste the Identifier from Unifize

    1. Complete setup.

    Return to the Unifize SSO configuration page and fill in the tenant fields with the values from your IdP:

    1. Click Save in the Unifize SSO configuration panel.

    2. Open a new private/incognito browser window.

    3. Go to https://app.unifize.com and enter an email address that belongs to the domain you configured.

    4. You should be redirected to your IdP's login page.

    If your organization uses more than one identity provider tenant (for example, separate Entra ID directories for different business units), you can add multiple tenants to a single Unifize org.

    1. In Org Settings β†’ SSO, click Add Tenant.

    2. Repeat Steps 2–5 for each additional tenant, using the credentials and domain(s) for that tenant.

    3. Each tenant will have its own Domain, Microsoft Entra Identifier, Login URL, and Certificate.

    This table describes every field in the SSO tenant configuration panel and what is expected in each.

    The SSO configuration page labels were updated to match Microsoft Entra ID's SAML setup terminology. If you configured SSO previously, use this table to find the fields you are familiar with.

    Understanding the flow helps you diagnose issues and configure your IdP correctly.

    1. User enters their work email on the Unifize login screen.

    2. Unifize checks the email domain against all configured SSO tenants for your org.

    3. If a matching tenant is found, the user is redirected to that tenant's Login URL.

    4. The IdP authenticates the user (with MFA if your IdP policy requires it).

    If a user's email address is updated in Unifize and their new domain belongs to a different SSO tenant, Unifize will automatically migrate them to the correct tenant.

    Practically, this means:

    • Updating a user's email in Unifize will re-evaluate which tenant they belong to.

    • If their new domain maps to a different tenant, their account is migrated to that tenant automatically.

    • No manual re-configuration is needed after an email domain change.

    Log in with your corporate credentials and confirm you land back in Unifize.

    The IdP sends a SAML assertion back to Unifize's Reply URL (ACS URL).

  • Unifize validates the assertion using the Certificate (Base64) you provided.

  • The user is logged in and redirected to their workspace.

  • Field in Unifize

    Where to use it in your IdP

    Example value

    Identifier (Entity ID)

    Application Entity ID / Audience URI

    unifize-866-saml

    Reply URL (Assertion Consumer Service URL)

    ACS URL / Reply URL

    Field in Unifize

    What to enter

    Where to find it in your IdP

    Domain

    The email domain for this tenant (e.g., yourcompany.com). Users with this domain will be routed to this tenant's IdP.

    Your org's email domain β€” not from the IdP

    Microsoft Entra Identifier

    The Entity ID of your IdP application

    Field

    Description

    Required

    Domain

    The email domain mapped to this tenant. Users with this domain are forced through SSO. Example: yourcompany.com

    Yes β€” per tenant

    Microsoft Entra Identifier

    Previous Label

    Current Label

    Service Provider Entity ID

    Reply URL (Assertion Consumer Service URL)

    Org SSO URL

    Sign on URL

    Entity ID

    Symptom

    Likely Cause

    What to Check

    User not redirected to IdP β€” sees password field instead

    Email domain not mapped to any SSO tenant

    Confirm the domain is entered correctly in the tenant's Domain field in Org Settings β†’ SSO

    SAML error / assertion validation failure

    Step 1 β€” Open SSO Settings in Unifize

    Step 2 β€” Collect Values from Unifize to Configure Your IdP

    Step 3 β€” Configure the Enterprise Application in Your IdP

    Microsoft Entra ID (Azure AD)

    Okta

    Google Workspace

    Step 4 β€” Enter Your IdP Details into Unifize

    Step 5 β€” Save and Test

    Adding Additional Tenants

    SSO Configuration Reference

    Field Reference

    Field Label Changes (Previous vs. Current)

    How Authentication Works β€” Admin Overview

    User Email Updates and Tenant Migration

    Troubleshooting

    https://app.unifize.com/__/auth/handler

    Sign on URL

    Sign-on URL / Login initiation URL

    https://app.unifize.com/sso-redirect?slug=<your-org-slug>

    Entra: 'Microsoft Entra Identifier' in the Set up section

    Login URL

    The IdP's SAML login endpoint

    Entra: 'Login URL' in the Set up section

    Certificate (Base64)

    The SAML signing certificate from your IdP. Must begin with -----BEGIN CERTIFICATE----- and end with -----END CERTIFICATE-----

    Downloaded from IdP in Step 3

    The Entity ID from your IdP. Identifies the IdP application to Unifize. Also called 'Identity Provider Entity ID' in Okta and 'Entity ID' in Google Workspace.

    Yes

    Login URL

    The SAML login endpoint of your IdP. Unifize redirects users to this URL to begin authentication.

    Yes

    Certificate (Base64)

    The X.509 signing certificate from your IdP, in Base64 format. Used to verify the SAML response. Must start with -----BEGIN CERTIFICATE----- and end with -----END CERTIFICATE-----

    Yes

    Identifier (Entity ID)

    Read-only. Unifize's own SAML Entity ID. Copy this into your IdP's enterprise application configuration.

    Provided by Unifize

    Reply URL (ACS URL)

    Read-only. The Assertion Consumer Service URL where your IdP sends the SAML response. Copy this into your IdP.

    Provided by Unifize

    Sign on URL

    Read-only. A direct login link that triggers SSO for your org. Unique to the org; defaults to the first configured tenant. For tenant-specific links, append &domain=<domain>.

    Provided by Unifize

    Microsoft Entra Identifier

    SSO URL

    Login URL

    Certificate

    Certificate (Base64)

    Certificate mismatch or expired certificate

    Re-download the Base64 certificate from your IdP and update it in Unifize

    Login loop β€” user keeps being redirected

    ACS URL or Identifier mismatch between IdP and Unifize

    Verify the Reply URL and Identifier in your IdP match exactly what Unifize shows

    User redirected to wrong tenant's login

    Email domain mapped to the wrong tenant

    Review domain assignments across all configured tenants in Org Settings β†’ SSO

    Sign on URL routes to wrong tenant

    URL defaults to first tenant when multiple are configured

    Use the domain-scoped URL format: /sso-redirect?slug=<nick-name>&domain=<domain>

    User cannot complete digital signature

    OTP not delivered β€” email mismatch or spam filter

    Verify the user's email in Unifize matches their IdP email; check spam/junk folder

    Mobile login stalls after IdP redirect

    Outdated app version or redirect handling issue

    Ask the user to force-close and reopen the Unifize app, and update to the latest version