SSO and MFA
Sign in with SSO (single sign-on), require MFA (also called 2FA), and map groups to ProvenTen roles.
SSO stands for single sign-on. People sign in once with the company login they already use (for example Microsoft Entra ID or Okta), then open ProvenTen without a separate password. You control who gets in from that identity provider. SSO is the right default for Enterprise.
Set up SSO (single sign-on)
- Open Admin → Security → SSO. ProvenTen uses SAML 2.0.
- Create an application in your identity provider (for example Microsoft Entra ID or Okta) and exchange metadata.
- Map groups to Admin, Librarian, and Seller. Test with one user in each role.
- Turn on SSO for the workspace and keep a break-glass admin account you can still use if the IdP is down.
MFA (also called 2FA)
MFA stands for multi-factor authentication: after the password, the person confirms it is them with a second check, such as an authenticator app or a device prompt. Many people know this as 2FA (two-factor authentication). Same idea, two names. In ProvenTen and in most identity providers, the setting is labelled MFA.
If users sign in with email and password (Growth, or before SSO is live), require MFA / 2FA in Admin → Security. When SSO is on, enforce it in the identity provider — do not run two competing MFA or 2FA prompts.
Related guides
- Users and roles
Admin, librarian, and seller access — who can see advocates and who can change the library.
- Sign-in problems
Wrong workspace, SSO loops, MFA prompts, and invites that never arrive.
- Enterprise rollout
A practical sequence for SSO, roles, import, CRM, and go-live with your ProvenTen team.