How to Set Up Single Sign-On (SSO) for EasySignage?

Learn how to connect EasySignage to your identity provider with SAML 2.0 or OIDC, so your team signs in with existing company credentials.

Single Sign-On (SSO) lets your team sign in to EasySignage with the credentials they already use for your company’s identity provider, instead of a separate EasySignage password. You create an application in your identity provider, connect it to EasySignage with SAML 2.0 or OIDC, verify your email domain, and optionally require everyone on that domain to use it.

SSO is included on the Enterprise plan.

 

What do I need before I start?

  • Admin access to your EasySignage account
  • Admin access to your identity provider (Microsoft Entra/Azure AD, Okta, OneLogin, Google Workspace, and others that support SAML 2.0 or OIDC)
  • Access to your domain’s DNS settings, to add one TXT record proving you own the domain

 

How do I turn on SSO for my account?

  • Sign in to EasySignage as the account admin and go to Settings → Single Sign-On
  • In your identity provider, create a new SAML 2.0 or OIDC application
  • Copy the Reply URL / ACS URL from the EasySignage SSO page into your identity provider, and choose an Identifier (Entity ID) to use in both systems
  • Back in EasySignage, choose the protocol, enter a display name, add your email domain, and fill in the fields from your identity provider (SP Entity ID, IdP Entity ID, SSO URL, and certificate for SAML; Issuer URL, Client ID, and Client Secret for OIDC)
  • Click Save configuration

 

How do I verify my domain?

SSO doesn’t activate until you prove you own the email domain.

  • After saving, EasySignage shows a Domain verification panel with a TXT record (Host/Name and value)
  • Add that TXT record with your DNS provider
  • Back in EasySignage, click Verify domain

A green Verified badge means SSO is active. DNS changes can take a few minutes to propagate, so wait 5 to 10 minutes and try again if verification fails right away.

 

Which identity providers work with EasySignage SSO?

Any provider that supports SAML 2.0 or OpenID Connect, including Microsoft Entra ID (Azure AD), Okta, OneLogin, Ping Identity, Google Workspace, JumpCloud, and Auth0. SAML 2.0 is the most common choice for enterprise SSO if your provider supports both protocols.

 

How do I require everyone to use SSO?

Once your domain is verified, an Enforce SSO for these domains switch appears in the Domain verification panel. Turn it on and users on that email domain can only sign in through SSO, password and social logins are blocked for them. Account admins stay exempt, so you can’t lock yourself out while testing.

 

Can I use more than one email domain?

Yes. Add each domain in the Email domains field, and verify each one with its own DNS TXT record.