Single sign-on (SSO) for form respondents

Put a form behind a company directory, so only that company's staff can open it and every response records who signed in.


This is about the people who fill in your forms. To let your own team sign in to Formester itself, see Single sign-on (SSO) for signing in to Formester. Respondents who sign in here never get a Formester account, and they only reach the forms you assign to the connection.


Available on: Enterprise. You'll need: a Formester owner or admin.


Before you begin


Connect a directory and activate it first. Set up single sign-on (SSO) with Microsoft Entra covers that from start to finish.


Only active connections can be chosen on a form.


Turn it on for a form


The sign-in field is a page, not an element, so you will not find it under Add Elements.


  1. Open the form and select Add Page, then Login Page.


The new page starts in password mode and says No password has been set yet! That is expected, and the next step changes it.


  1. Select the login field on the page to open its settings.
  2. Under Login Type, choose SSO.
  3. In Identity provider, choose your connection.


Formester confirms which directory now guards the form, and shows the date the connection was last verified.


The login field settings with SSO chosen and an identity provider selected


  1. Edit Field Label and Description if you want different wording. They default to "Sign in to continue" and "Use your work account to open this form."
  2. Select Publish.


What your respondents see


Opening the form link shows a sign-in card instead of your questions:


The published form showing a sign in card with a Continue with your work account button


Selecting Continue with your work account sends them to their own organization's sign-in page and brings them straight back. The form then shows their name and email marked verified, and the questions become available.


The form after signing in, showing the respondent's verified identity above the Submit button


Check it works


Open the published form link yourself, in a private window, and sign in with an account from the connected directory. You should land back on the form with your identity shown as verified.


Troubleshooting


Respondents always see the same short message when sign-in is refused, so work through the causes below rather than reading anything into the wording.


Everyone is refused, including your own staff. Most often the directory has not approved Formester yet. Reopen the connection and use Approve Formester in your directory.


Only some people are refused. The directory may restrict who is allowed to use Formester. Ask whoever administers it whether the people being refused have been assigned to the application.


Contractors and other invited accounts are refused. Turn on Allow guest accounts on the connection. If your own staff are refused this way too, the directory is not telling Formester who is staff and who is a guest, which is a missing claim on the connection. See Set up single sign-on (SSO) with Microsoft Entra.


Sign-in opens and then returns to the sign-in card. The page was probably left open long enough for the attempt to expire. Reload the form and sign in again.


Nobody can open the form any more, and nothing changed in the directory. Check that the connection is still active on the Single Sign-On page, and that your plan still includes single sign-on. Disabling a connection removes access immediately, including for people part-way through answering.


Good to know


  • A form uses one connection at a time. Switching a form back to password protection removes the assignment.
  • A connection cannot be deleted while a form is still using it. Formester tells you how many forms are assigned.
  • Responses already collected keep the respondent details recorded at the time they were submitted, even if you later disable or delete the connection.

Updated on: 08/09/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!