> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.formester.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Single sign-on (SSO) for form respondents

Put a form behind a company directory, so only that company's staff can open it and every response records who signed in.

This is about the people who fill in your forms. To let your own team sign in to Formester itself, see [Single sign-on (SSO) for signing in to Formester](https://help.formester.com/en/article/single-sign-on-sso-for-signing-in-to-formester-t6ll0n/). Respondents who sign in here never get a Formester account, and they only reach the forms you assign to the connection.

**Available on:** Enterprise. **You'll need:** a Formester owner or admin.

## Before you begin

Connect a directory and activate it first. [Set up single sign-on (SSO) with Microsoft Entra](https://help.formester.com/en/article/set-up-single-sign-on-sso-with-microsoft-entra-j4mqpk/) covers that from start to finish.

Only active connections can be chosen on a form.

## Turn it on for a form

The sign-in field is a page, not an element, so you will not find it under **Add Elements**.

1. Open the form and select **Add Page**, then **Login Page**.

The new page starts in password mode and says **No password has been set yet!** That is expected, and the next step changes it.

2. Select the login field on the page to open its settings.
3. Under **Login Type**, choose **SSO**.
4. In **Identity provider**, choose your connection.

Formester confirms which directory now guards the form, and shows the date the connection was last verified.

![The login field settings with SSO chosen and an identity provider selected](https://storage.crisp.chat/users/helpdesk/website/-/1/5/6/e/156e23ff3485c400/04-login-type-sso_wop1p8.png)

5. Edit **Field Label** and **Description** if you want different wording. They default to "Sign in to continue" and "Use your work account to open this form."
6. Select **Publish**.

## What your respondents see

Opening the form link shows a sign-in card instead of your questions:

![The published form showing a sign in card with a Continue with your work account button](https://storage.crisp.chat/users/helpdesk/website/-/1/5/6/e/156e23ff3485c400/05-respondent-signin_1wrcnlq.png)

Selecting **Continue with your work account** sends them to their own organization's sign-in page and brings them straight back. The form then shows their name and email marked verified, and the questions become available.

![The form after signing in, showing the respondent's verified identity above the Submit button](https://storage.crisp.chat/users/helpdesk/website/-/1/5/6/e/156e23ff3485c400/06-respondent-verified_1o7769h.png)

## Check it works

Open the published form link yourself, in a private window, and sign in with an account from the connected directory. You should land back on the form with your identity shown as verified.

## Troubleshooting

Respondents always see the same short message when sign-in is refused, so work through the causes below rather than reading anything into the wording.

**Everyone is refused, including your own staff.** Most often the directory has not approved Formester yet. Reopen the connection and use **Approve Formester in your directory**.

**Only some people are refused.** The directory may restrict who is allowed to use Formester. Ask whoever administers it whether the people being refused have been assigned to the application.

**Contractors and other invited accounts are refused.** Turn on **Allow guest accounts** on the connection. If your own staff are refused this way too, the directory is not telling Formester who is staff and who is a guest, which is a missing claim on the connection. See [Set up single sign-on (SSO) with Microsoft Entra](https://help.formester.com/en/article/set-up-single-sign-on-sso-with-microsoft-entra-j4mqpk/).

**Sign-in opens and then returns to the sign-in card.** The page was probably left open long enough for the attempt to expire. Reload the form and sign in again.

**Nobody can open the form any more, and nothing changed in the directory.** Check that the connection is still active on the **Single Sign-On** page, and that your plan still includes single sign-on. Disabling a connection removes access immediately, including for people part-way through answering.

## Good to know

* A form uses one connection at a time. Switching a form back to password protection removes the assignment.
* A connection cannot be deleted while a form is still using it. Formester tells you how many forms are assigned.
* Responses already collected keep the respondent details recorded at the time they were submitted, even if you later disable or delete the connection.