Skip to content

Your organisation

Single sign-on

Set up SSO with Microsoft Entra ID or any OIDC or SAML provider: verify your domain, add the provider, and require it.

Single sign-on lets your people sign in to Typestream with your own identity provider, and lets you require it. It works with Microsoft Entra ID and any OIDC or SAML provider.

Everyone can already sign in with a Microsoft account. Set up SSO when you want your organisation's own provider to decide who gets in.

You need to be an owner or admin of the organisation, and able to add a DNS record for your email domain.

1. Verify your domain

In Settings → SSO, add your email domain, such as northlight.example. Typestream shows a TXT record to add to the domain's DNS, with copy buttons. Add it with your DNS host, then click Verify. The status updates as Typestream checks; DNS changes can take a few minutes to appear.

Verifying proves the domain is yours. Once it's verified, people who sign in with an address at that domain land in your organisation automatically.

2. Add your provider

Choose OIDC or SAML, and follow the steps on the page. For Microsoft Entra ID, the page walks you through each screen:

  1. In the Entra admin centre, register an application for Typestream.
  2. Copy the redirect URI Typestream shows into the app registration.
  3. Copy the app's client id, client secret and issuer (for OIDC), or its metadata URL (for SAML), back into Typestream.
  4. Sign in once with SSO yourself, in a private window, before anyone relies on it.

For another OIDC provider you need the same three values: the issuer, a client id and a client secret. For SAML you need the provider's metadata URL or XML.

3. Sign in with SSO

On the sign-in page, choose Continue with SSO and enter your work email. Typestream finds your organisation's provider from the domain and sends you there.

New people who sign in this way join your organisation as members. An admin can change their role in Settings → Members.

4. Require SSO

Turn on Require SSO to make your provider the only way in for addresses at your verified domain. Before you do, the page tells you who it affects: anyone at the domain who signs in with a password or a Microsoft account is asked to use SSO from their next sign-in.

Keep one owner able to sign in another way, such as an address outside the domain, in case the provider has a problem.

Changes are audited

Adding, changing or removing a provider, verifying a domain, and turning Require SSO on or off each appear in the organisation's audit log, with who did it and when.