Single Sign On (SSO)

These are the SSO mechanisms in TOS.

  • External SAML Authentication: Allows users to log into TOS after being authenticated by an external identity provider (IDP) - Okta or Azure.

  • Internal SSO Authentication: Allows users to log in once to all TOS components (SecureTrack, SecureChange, SecureApp, and extensions), using the same credentials. This feature is enabled by default.

  • SecureChange with external authentication provider: This mechanism enables users to log into SecureChange separately using an external authentication provider. However, this feature is not compatible with TOS SSO. You can have TOS SSO or a separate login for SecureChange, but not both.

External SAML authentication only applies to SecureTrack, unless you also use internal SSO authentication to make it apply to all TOS modules - SecureTrack, SecureChange, SecureApp, and extensions.