Skip to content

How-to guide

Setting up SSO

For the volunteer who already runs Google Workspace or Microsoft Entra for the group. Adults with an address on that domain can use the SSO button after they type their email — instead of another Scout Suite password.

  1. Start from Single sign-on

    Under Settings → Single sign-on, the domain is taken from the group contact email — set that first if the page asks you to. You can add one OIDC provider and one SAML provider.

  2. Fill in what your identity provider gave you

    Both types need an Issuer. OIDC also needs Client ID, Client secret, a Discovery endpoint, and scopes (they default to openid, email and profile). SAML needs Entry point, Audience and Certificate. Create provider.

  3. Register the redirect URI the other way

    Configured providers show the Redirect URICopy it into the app registration on Google, Entra, or wherever you issued the client. After that, adults on that domain can use the SSO button on sign-in once they've entered their email.

    Microsoft Teams in-app calling on the same page is a different Entra app, not login SSO — skip it unless you specifically want Teams meetings inside Scout Suite.

Setup

More in this topic

Districts, WordPress, OSM, SSO, the API, privacy mode, and the assistant.