Overview
With single sign-on (SSO), Users sign in to Mobaro with their company account instead of a Mobaro password. Once Mobaro has set up SSO for your organization, you move Users over by inviting them. Ticking Require single sign-on on a User Group invites every member automatically, so you can roll SSO out team by team.
At a glance |
|
Who can do this | Group setting: Super Users, a Role with User Groups › Modify, or the group's Administrators. Inviting from Users: Super Users. |
Where | Administrate › User Groups › group › Single Sign-On (SSO); Administrate › Users |
Works on | Backend (web). Sign-in applies to the Backend and Mobile app. |
Availability | Add-on — ask your CSM to enable Single Sign-On (SSO) |
💡 Why this matters: Moving everyone to SSO at once is risky. Inviting by User Group lets you start with a pilot team, check that sign-in works, then add more groups on your own schedule.
Before you begin
SSO must be set up for your organization. Mobaro connects your identity provider. You can't configure it yourself in the Backend. Ask your CSM or Mobaro Support.
Members must already be Mobaro Users. Requiring SSO doesn't create Users. Create each User in Mobaro first, with the same email address they have in your identity provider.
Members must be able to sign in with your identity provider. Check with your IT team that each person has an account there that's allowed to use Mobaro.
Require SSO for a User Group
1. Open the User Group
Go to Administrate › User Groups and open an existing group, or create one. See Create and manage User Groups.
2. Add the members
Add each User who should sign in with SSO.
3. Tick Require single sign-on
In the Single Sign-On (SSO) panel, tick Require single sign-on and save. The panel only appears when your organization has SSO.
Within a few minutes, Mobaro queues an invitation for every member who doesn't have an SSO status yet, and emails it to them. New Users you create in the group get Single Sign-On (SSO) as their sign-in method.
🛑 Critical: When a member accepts the invitation, their Mobaro password stops working and they can only sign in through your identity provider. Before you tick Require single sign-on, confirm with a small group that SSO sign-in works, or members can be locked out.
Track invitations
The SSO Status column on Administrate › Users shows where each User is. Use its filter to list Users by status.
SSO Status | What it means |
Queued | The invitation is waiting to be sent. Mobaro sends queued invitations in batches every minute. |
Pending | The invitation email has been sent. Click Pending to send it again. |
Accepted | The User has signed in with SSO. From now on they sign in with their company account. |
To invite Users without requiring SSO on their group, a Super User can click Invite to sign in with SSO on the Users page, choose User Groups, and untick any members to leave out. Users who are already Queued, Pending or Accepted are skipped. If a User's SSO Status stays empty after an invitation, invite their group again.
What changes for members
Until they accept the invitation, members keep signing in with their Mobaro password.
After they accept, they sign in with their company account on the web and in the app. Their password is managed by your company, so Mobaro's Change Password and Forgot password? don't apply to them. See Change or reset your Mobaro password.
A mass password change skips Users who sign in with SSO.
⚠️ Heads-up: Removing someone from the group, or unticking Require single sign-on, doesn't move Users back to password sign-in. It only stops new invitations. An Accepted User keeps their SSO status. Contact Mobaro Support if someone needs a Mobaro password again.
Best practices
Start with a small pilot group, check that its members can sign in with SSO, then require SSO for more groups.
Make sure each User's email in Mobaro matches their email in your identity provider before you invite them.
Keep at least one Super User who signs in with a password, so someone can still make changes if SSO sign-in has a problem.
Frequently asked questions
What is SSO, and how do we get it?
SSO lets your Users sign in to Mobaro with their company account. It's an add-on: ask your CSM to enable Single Sign-On (SSO). Mobaro then connects your identity provider, and you invite Users by User Group.
Does requiring SSO create new users automatically?
No. Members must already exist as Mobaro Users. Requiring SSO only invites existing members of the group to switch to SSO sign-in.
Our users are on the "not yet migrated to new sign-in" list. Do they need SSO?
No. That list, from Download list of users not yet migrated to new sign-in on the Users page, is about Mobaro's own sign-in, not SSO. Only Super Users can download it.
How can I reset a user's password if they sign in with SSO?
You can't in Mobaro. Once they've accepted SSO, their password belongs to your company account. Ask your IT team to reset it in your identity provider.
I want to create a regular user with a password, not SSO. How?
Choose Password as the sign-in method when you create the User. If you add them to a User Group with Require single sign-on, the sign-in method is set to Single Sign-On (SSO) instead.
How do I turn off single sign-on?
Untick Require single sign-on on the User Group to stop new invitations. Users who already accepted stay on SSO, so contact Mobaro Support to move them back or to turn off SSO for your organization.
