Overview
Active Steward™ supports single sign-on (SSO) using OAuth 2.0 and OpenID Connect (OIDC). Microsoft Entra ID (formerly Azure AD) and Google are supported. If you use another OpenID Connect identity provider, talk to us during onboarding.
With SSO, your identity provider authenticates your users, so your password rules, multi-factor authentication and conditional access apply to Active Steward™ sign-in.
How it works
-
Choose SSO
The user goes to your Active Steward™ address and chooses to sign in with their organisation account.
-
Authenticate with your provider
They are redirected to your identity provider and sign in using the methods you require, such as MFA or passwordless sign-in.
-
Token returned
Your identity provider returns a signed token to Active Steward™ confirming who the user is.
-
Session and permissions
Active Steward™ matches the user to their existing account by email address, starts a session and applies the role and partition access held on that account.
What you need to provide
An administrator with rights to register applications in your identity provider will need to:
- Register Active Steward™ as an application in your identity provider.
- Enter the redirect (reply) URL that we give you.
- Send the following to the Active Steward™ onboarding team:
- Issuer or discovery URL (for Entra ID,
https://login.microsoftonline.com/{tenant}/v2.0). - Client ID and, where used, the client secret for the application registration.
- Scopes: normally
openid,emailandprofile. - Which claims identify the user's name and email address, and optionally their groups.
- Issuer or discovery URL (for Entra ID,
- Grant only the minimum scopes needed.
- Test with a small group of users before switching everyone over.
The onboarding team can provide step-by-step guidance and will help you validate the connection.
Automatic user provisioning (SCIM)
With Microsoft Entra ID you can also provision users automatically using SCIM 2.0:
- People assigned to the Active Steward™ application in Entra ID get an account, and people who are unassigned or disabled are deactivated.
- Provisioned accounts are never permanently removed: a user deleted in Entra is disabled and hidden, so their history stays attributable.
- New users get a fixed default role, or a role taken from their Entra groups the first time they sign in. After that, roles are managed by your administrators in Active Steward™.
- Provisioning uses an API key that works only for provisioning, and each change is recorded against the administrator who created the key.
Accounts can also be created and managed by hand in Active Steward™ if you prefer.
Security and operational notes
- MFA: enforced by your identity provider. Active Steward™ follows whatever policies you apply.
- Passwords: accounts provisioned through SCIM have no Active Steward™ password and sign in by SSO only.
- Sessions: they end after a configurable period of inactivity.
- Authorisation: separate from authentication. Your administrators assign roles and partition access in Active Steward™.
- Audit: sign-ins are logged by your identity provider, and Active Steward™ logs each sign-in attempt and records each user's last sign-in.
- Fallback: if your identity provider is unavailable, contingency sign-in can be arranged by prior agreement.
- Without SSO: users sign in with a password, with optional time-based two-factor authentication.
Benefits for your organisation
- Add, suspend and remove users centrally in your identity provider.
- No extra password for users to remember.
- Your MFA and conditional access policies apply.
- Your identity provider's sign-in logs show who signed in and when.
For network settings, see client IT requirements.