---
title: "Account: External Authorization (SSO)"
slug: "account-external-authorization-sso"
tags: ["account settings"]
updated: 2024-05-16T17:28:11Z
published: 2024-05-16T17:28:11Z
canonical: "support.smarteru.com/account-external-authorization-sso"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://support.smarteru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Account: External Authorization (SSO)

This feature is not included with all accounts. Please contact our [Success Desk](mailto:success@neovation.com) if you would like to add this feature to your account.

External Authorization allows you to configure a Single Sign On (SSO) connection between a third-party system (e.g., [Google](/v1/docs/sso-google-openid), [Microsoft ADFS](/v1/docs/sso-active-directory-federation-services), [Okta](/v1/docs/sso-okta), or any SAML 2.0 compatible identity provider with IDP-initiated SSO) to SmarterU. By establishing SSO, your learners will not need to have separate login credentials for SmarterU.

SSO only refers to authentication. There are also options to establish automatic [user provisioning/de-provisioning](/v1/docs/user-sync-integrations).

When you [edit your account's settings](/v1/docs/editing-your-account-settings), the External Authorization accordion of the Account Profile workscreen includes the following settings.

![Graphical user interface, text, application Description automatically generated](https://cdn.document360.io/7efaadab-fef6-4186-806a-2ca14c9ce9ea/Images/Documentation/account-external-authorization-sso-image-ccxdzo1c.png)

## Settings

Be sure to click **Save** after changing these settings.

### Enable External Authorization

Check to allow Single Sign-On from a third-party system to SmarterU.

SmarterU currently supports Single Sign-On through a number of providers. Each provider must be enabled in your account separately. The currently supported Single Sign-On providers are:

- [SAML 2.0](/v1/docs/sso-saml-20)
- [OpenID for Google Applications](/v1/docs/sso-google-openid)
- [Azure AD B2C OpenID](/v1/docs/sso-azure-active-directory-b2c)
- [SmarterU API](/v1/docs/api)

A separate section will appear for each Single Sign-On provider enabled for your account.

### Master Login Control

This setting is only applicable if the [Enable External Authorization setting](/v1/docs/account-external-authorization-sso#enable-external-authorization) is checked. Select one of the following options:

- SmarterU - users will be allowed to log in ONLY through SmarterU. Your remote login page will display your original login form.

![Login Master Login Control - SmarterU 20230711](https://cdn.document360.io/7efaadab-fef6-4186-806a-2ca14c9ce9ea/Images/Documentation/Login%20Master%20Login%20Control%20-%20SmarterU%2020230711.png)

- External Authorization - users will be allowed to log in ONLY through your Single-Sign On provider. Your remote login page will display the text from the [Login Message field](/v1/docs/account-external-authorization-sso#login-message) and a button that will redirect the users to the URL specified in the [Login URL field](/v1/docs/account-external-authorization-sso#login-url).

![Login Master Login Control - External 20230717](https://cdn.document360.io/7efaadab-fef6-4186-806a-2ca14c9ce9ea/Images/Documentation/Login%20Master%20Login%20Control%20-%20External%2020230717.png)

When the External Authorization option is selected, the [password recovery link](/v1/docs/recovering-your-password) will not display on the login page. Users will need to contact an administrator to request a [password reset](/v1/docs/resetting-a-users-password). 

- Both -  users will be allowed to log in through SmarterU and your Single-Sign On provider. Your remote login page will display the text from the [Login Message field](/v1/docs/account-external-authorization-sso#login-message) and two buttons. The first button redirects users to the URL specified in the [Login URL field](/v1/docs/account-external-authorization-sso#login-url). The second button redirects users to the SmarterU portal login page.

![Login Master Login Control - Both 20230717](https://cdn.document360.io/7efaadab-fef6-4186-806a-2ca14c9ce9ea/Images/Documentation/Login%20Master%20Login%20Control%20-%20Both%2020230717.png)

- User-Specified - If selected, the display will be based on the user's [User Default Login setting](/v1/docs/user-login-information#user-default-login) for newly created users. This will allow you to specify the login option at the user level.

### User Default Login

This setting is only applicable if the [**Enable External Authorization** setting](/v1/docs/account-external-authorization-sso#enable-external-authorization) is checked.

If the [**Master Login Control** field](/v1/docs/account-external-authorization-sso#master-login-control) is set to *User-Specified*, SmarterU will look at the user attempting to log in to determine where the user can log in from. If the user does not have a [specified login setting (i.e., the **User Default Login** field for the user)](/v1/docs/user-login-information#user-default-login), the selected option below will be used.

- SmarterU - the default user login is SmarterU.
- External Authorization - the default user login is your Single-Sign On provider.

When the External Authorization option is selected, the [password recovery link](/v1/docs/recovering-your-password) will not display on the login page. Users will need to contact an administrator to request a [password reset](/v1/docs/resetting-a-users-password).

- Both - the default user login is SmarterU and your Single-Sign On provider

### Login URL

This setting is only applicable if [**Master Login Control**](/v1/docs/account-external-authorization-sso#master-login-control) and [**User Default Login**](/v1/docs/account-external-authorization-sso#user-default-login) are set to a value other than *SmarterU*. This is the URL that users will be redirected to when they click the Login button on the portal page.

### Customize Login Button Text

This setting is only applicable if [**Master Login Control**](/v1/docs/account-external-authorization-sso#master-login-control) is set to a value other than *SmarterU*. This is the label that displays on the login button.

### Customize Portal Login Button Text

This setting is only applicable if [**Master Login Control**](/v1/docs/account-external-authorization-sso#master-login-control) is set to *Both* or *User-Specified*. This is the label that displays on the portal's login button.

### Login Message

This setting is only applicable if the [**Master Login Control**](/v1/docs/account-external-authorization-sso#master-login-control) is set to *External* or *Both*, or if the [**User Default Login**](/v1/docs/account-external-authorization-sso#user-default-login) is set to *External*. Enter the login message that your account users will see.

## Related

- [Adding a User Manually](/adding-a-user-manually.md)
- [Editing Your Account Settings](/editing-your-account-settings.md)
- [External Authorization (SSO)](/external-authorization-sso.md)
- [Generating a Certificate Signing Request](/generating-a-certificate-signing-request.md)
- [SSO: Active Directory Federation Services](/sso-active-directory-federation-services.md)
- [SSO: Microsoft Entra ID](/sso-microsoft-entra-id.md)
- [SSO: Azure Active Directory B2C](/sso-azure-active-directory-b2c.md)
- [SSO: Google OpenID](/sso-google-openid.md)
- [SSO: GSuite](/sso-gsuite.md)
- [SSO: Okta](/sso-okta.md)
- [SSO: SAASPASS](/sso-saaspass.md)
- [SSO: Salesforce](/sso-salesforce.md)
- [SSO: SAML 2.0](/sso-saml-20.md)
- [SSO: SmarterU API](/sso-smarteru-api.md)
- [User Sync Integrations](/user-sync-integrations.md)
- [User: Login Information](/user-login-information.md)
