Single sign-on (SSO) lets users in your organization sign in to the Partner Control Center with your organization's identity provider (IdP). The Partner Control Center supports Security Assertion Markup Language (SAML) and OpenID Connect (OIDC), but only one method can be used at a time.
SSO in the Partner Control Center works the same way as SSO in the Esper console. If you've already set up SSO for a tenant, the process will look familiar. For tenant-level SSO, see Set Up Single Sign-On (SSO).
To set up SSO, you need the following:
- The Admin role in the Partner Control Center
- Administrative access to an identity provider (for example, Okta or Microsoft Entra ID)
In this article:
- SSO Setup Process
- Setting Up SAML
- Setting Up OIDC
- Completing SSO Setup
- Adding Users to SSO
- Deleting an SSO Connection
- About Session Timeouts
SSO Setup Process
The SSO setup process consists of:
- Adding a new connection in the Partner Control Center
- Choosing a connection type: SAML or OIDC
- Copying the Partner Control Center's service provider information to your IdP (SAML only)
- Entering your IdP's connection details in the Partner Control Center
- Accepting the SSO invitation
- Adding users
Setting Up SAML
Step 1: In the Partner Control Center, navigate to Single Sign-On (SSO) and click on Add New Connection.
Step 2: Under SSO Provider Information, select SAML.
Step 3: On the Service provider information step, copy the Assertion Consumer Service (ACS) URL and the Entity ID. Use the copy icon next to each field.
Step 4: In your IdP, create a new SAML application for the Partner Control Center (or open an existing one) and enter the following:
- The ACS URL in the single sign-on URL or reply URL field
- The Entity ID in the Entity ID or Audience URI field
- Email Address for the Name ID format
Step 5: From your IdP, copy the following:
- The IdP single sign-on URL
- The X.509 signing certificate, in PEM or CRT format
Step 6: Back in the Partner Control Center, select the checkbox for I have copied the service provider information over to the SSO provider and click on Continue.
Step 7: On the Connection details step, fill out the following fields:
- Connection Name: A name for the connection. We recommend using the name of your IdP.
- Sign-in URL: The single sign-on URL from your IdP.
-
X.509 Signing Certificate: The full certificate from your IdP, including the
-----BEGIN CERTIFICATE-----and-----END CERTIFICATE-----lines.
Step 8: Click on Create Connection. To change values from the previous step, click on Back.
Next, accept the SSO invitation. See Completing SSO Setup.
Setting Up OIDC
Step 1: In your IdP, create a new application. Choose OIDC and single-page application, and set the grant type to Implicit (hybrid).
Step 2: From your IdP, copy the following:
- Issuer URL. Learn more about Issuer URLs.
- Client ID
Step 3: In the Partner Control Center, navigate to Single Sign-On (SSO) and click on Add New Connection.
Step 4: Under SSO Provider Information, select OIDC. OIDC doesn't need any service provider information, so click on Continue.
Step 5: On the Connection details step, fill out the following fields:
- Connection Name: A name for the connection. We recommend using the name of your IdP.
- Issuer URL: The Issuer URL from your IdP.
- Client ID: The Client ID from your IdP.
Step 6: Click on Create Connection. To change your connection type, click on Back.
Next, accept the SSO invitation. See Completing SSO Setup.
Completing SSO Setup
After you create the connection, the Partner Control Center sends an SSO invitation to your email address. The connection is now active, and any user can use the connection start using SSO to log in if invited.
Step 1: Click on Ok, got it to close the dialog.
Step 2: Open the invitation email and click on the invitation link.
Step 3: Choose the SSO sign-in method. Choosing another method (such as password or Google) doesn't satisfy the SSO criteria.
Once you accept the invitation, you can enable SSO for all other users in your organization.
Adding Users to SSO
After you configure SSO, add users to both your IdP and the Partner Control Center.
Step 1: In your IdP, assign users to the Partner Control Center application.
Step 2: In the Partner Control Center, navigate to User Management and click on Invite New User. Enter the user's email address and choose SSO as the login method. Invited users receive an email with a link to sign in.
Until users accept their invitations, they appear in the Pending Invites tab.
Step 3: Ensure each user accepts the invitation and chooses the SSO sign-in method.
Once your organization switches to SSO only, users can sign in only with SSO. Ensure every user who needs access is added to both the Partner Control Center and your IdP.
Converting existing users to SSO
Invite existing users after you configure SSO. Once they accept their SSO invitations, switch to SSO only. To require SSO for every sign-in, delete other credentials after users accept their invitations.
Deleting an SSO Connection
You can delete an SSO connection at any time. When you do, users who sign in with SSO can no longer sign in to the Partner Control Center. They'll need to use Google authentication or Esper credentials (email and password) instead.
Before you delete a connection, ensure users have a non-SSO sign-in method available.
Step 1: If your organization allows only SSO, navigate to Single Sign-On (SSO) and click on Switch to All Sign-in Types.
Step 2: Sign in to the Partner Control Center with a non-SSO method (Google authentication or Esper credentials).
Step 3: Navigate to Single Sign-On (SSO) and click on Delete Connection.
Step 4: Type DELETE and click on Confirm.
Esper disables SSO sign-in for all users who signed in through SAML or OIDC. This process can take about 10 minutes. Ensure you also delete or reset the application in your IdP.
Deleting a connection doesn't delete users. To remove users, delete them from User Management. When you delete a user, all API keys associated with that user are also invalidated.
About Session Timeouts
Most IdPs support session lifetimes and timeouts. Once SSO is set up, you can manage session timeouts through your IdP. To learn more, see these articles from popular IdPs:
- Enforce a limited session lifetime for all policies - Okta
- Application session timeout interaction - Okta
- User Policy Management - OneLogin
Don't see your provider listed? Check your provider's documentation for session lifetime best practices.