A company that already has work accounts for email and other tools should not have to manage another set of passwords for HR. Rifena supports company sign-in with clear configuration and verification steps, so single sign-on can be switched on without locking anyone out.
Who this is for
For the company administrator working with the identity-system owner to configure and introduce company sign-in safely.
Outcome
Finish when the provider shows Active, one administrator identity and a distinct test identity both complete a fresh provider sign-in after enforcement, provider-side recovery has been confirmed, and the enforcement state matches the approved decision.
Rifena supports company sign-in through OpenID Connect or SAML 2.0; enforce SSO only after the provider status shows Active.
Secret values are entered only during configuration and are not shown again; keep at least one administrator able to sign in for recovery before enforcing SSO.
Before you start
Select the correct company and have the approved provider configuration ready. The identity provider must contain at least one administrator identity and a distinct test identity — ideally a second administrator — provisioned for the application, together with a provider-side recovery owner. Enforcement disables Rifena password sign-in for the entire company; the application has no break-glass exemption.
Steps
- Confirm that the administrator identity and distinct test identity are both provisioned at the identity provider, provider-side recovery is ready, and the provider owner can still reach the IdP administration console. Keep one current Rifena administrator session open until the rollback window has ended.
- Open single sign-on. If the page is read-only, review the status and hand configuration to someone with identity-security management access. With management access, select External identity provider, complete Organization key, then select OpenID Connect or SAML 2.0.
- Register the displayed Redirect URI for the OIDC application, or register the displayed Service provider details for SAML at the IdP. Complete the provider fields or select Import metadata, review the populated data, and enable the selected protocol.
- The Client secret field is write-only. Leave it blank to preserve a stored value; complete it only for initial setup or rotation on the Rifena screen. Never copy that value into documentation, support messages, or handoff notes.
- Keep Enforce SSO off, set Just-in-time provisioning and Allowed email domains according to the approved decision, then select Save changes. Confirm SSO configuration saved. and the Active state.
- Before enforcement, complete successful test sign-ins through the IdP in fresh or private sessions for both the administrator identity and the distinct test identity.
- From the retained administrator session, after the impact is approved and recovery is confirmed, enable Enforce SSO, select Save changes, and reload to confirm that the enforcement state remains saved.
- In fresh sessions, sign in through the IdP again with both the administrator identity and the distinct test identity. If either fails, return to the retained administrator session, turn off Enforce SSO, select Save changes, and verify that password sign-in is restored.
- If the retained administrator session is unavailable, stop and escalate immediately to the identity-security owner; do not assume provider-side recovery can reverse the Rifena configuration. Close the retained administrator session only after both tests pass or rollback is complete.
Check the result
The provider shows Active, the save confirmation appeared, the administrator identity and distinct test identity both sign in through the IdP in fresh sessions after enforcement, the recovery owner is recorded, and reloading preserves the approved enforcement state.
If you cannot continue
Stop before enforcement if the IdP is not ready, either identity has not completed a successful test sign-in, provider-side recovery is unavailable, an authenticated Rifena administrator session cannot be retained, or save access is missing. After enforcement, if either test fails, perform the rollback step immediately; if the retained session is lost, escalate the incident instead of making another change.
Handoff
Hand off the provider type, protocol, scope, saved and enforcement states, pre- and post-enforcement test results, any rollback result, recovery owner, and monitoring owner. Never hand off a password, client secret, private certificate, or authentication code.
Next
After company sign-in is stable, continue to personal-account protection or access troubleshooting.