Single Sign-On (SSO)
Single Sign-On (SSO) lets Engagement Cloud customers authenticate their users through their own Identity Provider (IdP) using OpenID Connect (OIDC), instead of a CoreMedia-specific username and password. SSO is available in both Engagement Cloud Studio (v3) and Contact Center and Analytics Studio (v4). It is enabled per account and per user.
Multi-Factor Authentication (MFA) can also be configured by the customer on their own Identity Provider, but it is not enforced by CoreMedia. This removes password-based authentication as a security and compliance blocker for enterprise and regulated-industry customers.
What you will learn
After reading the Single Sign-On (SSO) documentation, you will be able to:
- Understand how the SSO login flow works for end users, from entering an email to landing in the product.
- Request SSO activation for your account.
- Activate or revoke SSO for an individual user in the Teams App.
- Understand what happens when a user's email address changes.
- Recognize the error messages users see when SSO login fails.
- Understand how SSO usage is billed.
Target audience
The Single Sign-On (SSO) documentation is for:
- Managers who activate or revoke SSO for an individual user on the General tab of the user's profile in the Teams App, and who see the SSO flag state and audit log for that user.
- End users (any role) who use the email-based SSO login flow to sign in to Engagement Cloud Studio (v3) or Contact Center and Analytics Studio (v4).
- The CoreMedia internal team, which activates SSO for a customer account.
Purpose
Password-only login is increasingly seen as a security risk and an operational burden by enterprise and regulated-industry customers, and is often a blocker during procurement and security review. SSO addresses this by letting customers authenticate Engagement Cloud users through their own Identity Provider using OpenID Connect (OIDC), so the customer retains full ownership of identity and access policy.
SSO also reduces password-management overhead and related support tickets. Customers can additionally configure Multi-Factor Authentication (MFA) on their own Identity Provider if they choose to; CoreMedia does not require or enforce MFA.
How it works
SSO is activated in two stages and then used at login:
| Stage | Who | Description |
|---|---|---|
| 1. Account activation | CoreMedia internal team | SSO is configured for the customer's account with the customer's Identity Provider details. See Activating SSO for your account. |
| 2. Per-user activation | Manager | A Manager enables the SSO ENABLED flag on an individual user's profile in the Teams App. See Activating or revoking SSO for a user. |
| 3. Login | End user | The user enters their email on the login page; once a recognized SSO domain is detected, they continue with their Identity Provider. See Signing in with SSO. |
Every SSO flag change, manual or automatic, is recorded in the audit log with who or what triggered it, the affected user, and a timestamp.
Supported identity providers
The following Identity Providers are supported:
- Microsoft Entra ID (Azure AD)
- Okta
- Ping Identity
- Auth0
- Google Identity
More about SSO
- A Manager can revoke SSO for one user without any database access.
- A user's SSO flag is automatically reset if their email address changes, preventing lockout from a stale Identity Provider mapping.
Note: A user must have a valid email address on their profile before SSO can be activated for them.
Billing
SSO usage is billed through a dedicated SecureID (SSO Users) pricing rule. The rule meters the number of users with SSO enabled, not the number of SSO logins.
Key concepts
| Term | Description |
|---|---|
| SSO | Single Sign-On. One login gives a user access to multiple applications without re-entering credentials. |
| MFA | Multi-Factor Authentication. Login requires a second proof of identity. Can be configured by the customer on their own Identity Provider; not enforced by CoreMedia. |
| OIDC | OpenID Connect. The identity protocol built on OAuth 2.0 used for SSO. |
| IAM | Identity and Access Management. |
| IdP | Identity Provider. The system that holds and authenticates user identities, for example Entra ID or Okta. |
| Tenant | The logical customer boundary within Engagement Cloud. |
Related links
SSO Reference2 articles
Reference for the fields and messages related to Single Sign-On (SSO).