Single sign-on lets people sign in to your organization with your own identity provider instead of a 360Player password, and directory sync keeps the accounts in step with it.
Before you start
Your organization needs a Slug, set under Settings > General in Core settings. The slug is what makes your sign-in link unique, so nothing here works without one. You also need admin access to the identity provider itself.
Add an identity provider
Go to Settings > Single sign-on. With none set up you will see No connected identity providers yet.
Click Add identity provider.
Give it a Display name. This is what your users see on the sign-in screen, so name it after the thing they recognise.
Optionally set Required for roles to force particular roles to sign in this way. You can change this later.
Save. The provider appears in the list as Not yet connected.
Connect it
Open the provider's menu and pick Manage connection.
Select your provider from the list and follow its own setup steps. This part happens inside your provider's console, not in 360Player.
When it completes you are returned to the settings page, and a Login URL appears. Copy it and share it with your users — that link is how they sign in with SSO.
Connecting is not the same as switching on. A connected provider does nothing until you Enable SSO for the organization. Enable it when you are ready for it to start affecting how people sign in.
Directory sync
Once SSO is connected you can also sync accounts from the same directory, so joiners and leavers follow your provider rather than being maintained twice.
Open the provider's menu and pick Manage directory.
Follow Configure directory sync and connect the directory.
Use Enable directory sync to turn it on, and Disable directory sync to stop it.
Map your own fields
With a directory connected, you can map its attributes onto the user fields you have defined, so data arrives filled in rather than being chased.
Pick Edit attribute mappings from the provider's menu.
Click Add field mapping, choose one of your user fields, and pick the matching Directory Provider Value from Mappable Attributes.
Add another mapping for each field you want, then save.
Only fields you have created under Settings > User fields can be mapped — see Customize your user database for adding them.
Troubleshooting
People are still being asked for a 360Player password. The connection exists but SSO has not been enabled. That is the Enable SSO step above.
No Login URL. It appears only once the provider is actually connected, not when it has been added.
A field is not in the mapping list. Create it as a user field first.
No Single sign-on item in Settings. You do not have permission to manage identity providers. Ask a top-level administrator.
