> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.formester.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Single sign-on (SSO) for signing in to Formester

Point your organization at your Microsoft Entra directory so your team signs in to Formester itself with their work account, and require it once you have proved it works.

**Available on:** Enterprise. **You'll need:** a Formester owner or admin.

**Require SSO for this organization** stays switched off until you have signed in through the connection yourself, in the browser you are working in. That sign-in is what proves the requirement cannot lock you, or anyone else, out.

## Before you begin

* Connect a directory and activate it first. [Set up single sign-on (SSO) with Microsoft Entra](https://help.formester.com/en/article/set-up-single-sign-on-sso-with-microsoft-entra-j4mqpk/) covers both routes, using Formester's app or your own app registration. Only active connections can be used for signing in to Formester.
* One connection signs your team in. Choosing a second one replaces the first.

## Choose the connection your team signs in with

1. Select **Single Sign-On** in the left sidebar.
2. Scroll to **Sign in to Formester with SSO**.
3. Open **Connection used for app login** and choose your connection.

To turn Formester sign-in off again later, come back to this list and choose **Not set up, members sign in with a password**.

![The Sign in to Formester with SSO panel, showing the connection picker, the five sign-in verification checks, the Create accounts on first sign-in toggle, the portal login link, and the Require SSO for this organization toggle](https://storage.crisp.chat/users/helpdesk/website/-/1/5/6/e/156e23ff3485c400/01-app-login-panel_leza4l.png)

## Prove you can still get in

1. Select **Sign in with your own account**. Formester hands you to Microsoft.
2. Sign in with your own work account. You come back to the settings page, the badge reads **Verified**, and every line under **Sign-in verification** is ticked: **Authorization redirect**, **ID token signature valid**, **Account allowed to sign in**, **Email claim present**, **Account matched or created**.

If it stops part way, the step it stopped on is marked in red and the badge reads **Not completed** or **Verification failed**. Fix the connection, then select **Sign in again**.

## Decide who gets an account

Set **Create accounts on first sign-in**.

* **On**: a first sign-in creates a staff account, so anyone in your directory can get in.
* **Off**: only people who already have an account, or an open invitation, can sign in.

Someone who already has an account or an invitation keeps the role you gave them. Nothing takes a role from your directory.

## Hand out the sign-in link

Copy **Login link for your portal** and publish it where your team will find it, such as Microsoft My Apps or your intranet. It takes them straight to your directory and back into Formester.

If the panel says your organization has no workspace address yet, there is no link to hand out and you cannot require SSO. Contact support first.

## Require SSO for this organization

1. Turn on **Require SSO for this organization**. It stays unavailable until you have completed the sign-in above in this browser.
2. Read the confirmation and select **Require SSO**. The badge changes to **Required**.

![The Require SSO for this organization confirmation, explaining that everyone opens the organization through the connection from now on, that password, Google and Microsoft sign-in keep working but stop granting entry, that it applies to you as well, and that it can be turned off at any time](https://storage.crisp.chat/users/helpdesk/website/-/1/5/6/e/156e23ff3485c400/02-require-sso-confirm_ayzh07.png)

To lift it, turn the same toggle off. There is no confirmation and it is never refused, so you are not stuck if your directory stops working. Disabling or deleting the connection clears the requirement too.

## What happens next

Everyone opens this organization through your connection. Password, Google and Microsoft sign-in keep working, they just stop granting entry here, and any other organization someone belongs to is unaffected. Your public forms and the responses people submit to them are never gated, and signing out always works.

## Troubleshooting

| What you see | What to do |
| ---- |
| **Sign in through your company account first, so requiring it cannot lock you out** | Select **Sign in with your own account** and finish the sign-in, then turn the requirement on in the same browser. |
| **Activate this connection first** | The connection is not active yet. Test and activate it, then come back. |
| **Your directory signed in as ..., not the account you are using here** | Your work account resolves to a different Formester account. Point that directory account at this Formester account, or sign in here as the account it named, before requiring SSO. |
| **Formester sign-in verification did not complete** | The steps under **Sign-in verification** show where it stopped. |
| A member is told **You do not have a Formester account in this organization yet** | **Create accounts on first sign-in** is off. Invite them, or turn it on. |
| A member is told their directory **did not send an email address or a sign-in name** | Ask your IT administrator to set a mail address on that directory account. |
| A member is told **You are already signed in as a different Formester account** | They sign out of Formester, then open the sign-in link again. |
| A member is told **Your organization has used every seat on its plan** | Free a seat or upgrade. |

If a member cannot sign in and the message gives them a reference, ask them for it. Support can find that exact attempt.