User Roles Admin✗Staff contributor ✗External contributor ✗Pulse user 

This article explains Single Sign-On (SSO), which lets users sign in to multiple platforms with one set of credentials. It covers the advantages for users and firms, how to get SSO set up, and how to enforce SSO for all users.


Table of contents 

What is SSO?

SSO simplifies signing in across multiple platforms. A user signs in once with one set of credentials, and those same credentials give them access to other applications as well.

What are the advantages of SSO?

  • For users, the main advantage is that they do not have to create and remember a separate password for Silverfin, and can usually sign in with a single click.
  • For admin users, the main benefit is being able to manage user access outside Silverfin. For example, when an employee leaves the firm and their user is deactivated in the firm’s user system, access to all other SSO-integrated tools is revoked immediately, with no need for manual changes in other systems.

Setting up Silverfin with SSO means authentication to the Silverfin application is handled outside Silverfin. This gives the firm’s IT department control to set custom password rules (renewal, complexity, location), enable multi-factor authentication, or configure any other authentication-specific setting.

How do I set this up for my firm?

Ask your IT department to get in touch with the Silverfin SSO experts to set this up. The document attached at the bottom of this article has more detail.

We can set up:

  1. Azure AD
  2. Azure B2C
  3. OpenID Connect

Get in touch with your Customer Success Manager (CSM) with your requirements and we can get you set up.

How does SSO work once it's set up?

You can continue to add new users as usual. Existing Silverfin users can sign in with SSO straight away, as long as their email address matches between Silverfin and the SSO platform.

  • Administrators can require certain users to sign in with SSO only. If an SSO was selected when the user was created, that user must sign in to Silverfin with SSO and cannot sign in with their Silverfin username and password. Firm admins can see and set whether a user is required to use SSO in the user creation and user details screens.
  • In the User SSO settings section, you will find the ‘Require user to sign in with SSO’ checkbox. For firms with more than one SSO enabled, you can select a default SSO for the user. They can still sign in with the alternative SSO if their user email matches in both SSOs. The selected SSO also defines which welcome email is sent to the user.
  • Users who should be allowed to sign in with a username and password must have the ‘Require user to sign in with SSO’ option unchecked.
    Note: they will still be required to sign in with SSO in another firm if their email address is associated with that firm’s SSO.

To sign in with SSO, the user has to access Silverfin through an SSO subdomain, which is defined when you set up SSO. The URL is in the format [subdomain].getsilverfin.com, and you can find the subdomain in the SSO connection section.

How do I enforce SSO for all users?

If you have already configured SSO for your firm, you can enable the firm-wide SSO Enforcement feature. This requires all users, or all staff users, to sign in through SSO. The options for SSO Enforcement are:

  • Enforced for all users
    All users must sign in via SSO, regardless of their user SSO configuration.
  • Enforced for staff users
    All staff users must sign in via SSO, regardless of their user SSO configuration.
  • Not enforced
    All users sign in according to their user SSO configuration.

Please be aware that when SSO Enforcement is enabled, users are forced to sign in with SSO. A user who does not have an SSO account will not be able to sign in to their account. You will find the option in the SSO connections section under User configuration.

If a user tries to sign in with their username and password after SSO Enforcement is enabled, they will see a screen similar to this one, guiding them to the correct way to sign in: