Learnient supports SAML 2.0. If your identity provider speaks SAML, it will connect; there is no separate Google or Microsoft sign-in button to switch on.
Setting it up runs in two halves, and the screen is built that way: you create the provider and Learnient gives you two values, you take those to your identity provider, then you come back with three values from it.
Before you start
Section titled “Before you start”Everyone who will sign in this way must already exist in Learnient. Nobody is created automatically on first sign-in: an email address the account does not recognise is refused rather than enrolled.
Add your people first with Importing and updating users.
Connecting your identity provider
Section titled “Connecting your identity provider”-
Choose Admin at the top of the page, then Workspace in the left-hand menu and Security.
-
Set Advanced security option to Single sign-on. Until you do there is no single sign-on section on the screen at all: the field offers None, Two-factor authentication and Single sign-on, and only the last of those brings the provider settings out.
-
Choose Add Identity provider, enter a Name and save. Name is the only field on this window — the screen says so itself: “enter a name and save. Learnient will show an identifier and reply URL to paste into your identity provider before you add IdP login details”.
-
The provider now shows Pending IdP setup. Open its actions menu and choose View: it shows Identifier and Reply URL, both marked view only, each with its own Copy button.
-
In your identity provider, create a SAML application and paste in the Identifier and the Reply URL. Save it there. Nothing happens in Learnient during this step, and the View window points you back: “Next — open Edit and paste the identity provider login URL, entity ID and certificate”.
-
Back in Learnient, choose Edit Identity provider and fill in the three values your identity provider gives you: Login URL, Entity ID and Certificate (Base64). All three are required.
Entity ID is the one people get wrong. It is your identity provider’s own entity ID — in Microsoft Entra, the Microsoft Entra Identifier, which looks like
https://sts.windows.net/.... It is not the Identifier you copied out of Learnient in step 4. The two are easy to swap because you have just been handling the other one. -
Save. The provider moves to Ready.
The windows number themselves Step 1 for adding the provider and Step 3 for pasting the identity provider’s values, counting the work you do inside your identity provider as step 2. If you are following both at once, that is why the numbers differ from the list above.
Screenshot missingsso-provider-view
The View Identity provider window for a provider that has been saved but not yet configured, showing the read-only Identifier and Reply URL fields with their copy buttons, the status reading "Pending IdP setup", and the hint "Copy the identifier and reply URL into your identity provider's SAML configuration".
Expected at src/assets/screenshots/guides/set-up-single-sign-on/sso-provider-view.png
Turning it on for the account
Section titled “Turning it on for the account”Single sign-on is switched on for the whole account, not per person. It cannot be switched on until at least one provider is Ready.
Two-factor authentication and single sign-on cannot both be on, and the screen settles that by making them two values of one field rather than two switches: choosing either replaces the other. Your identity provider is where a second factor belongs once SSO is in use.
What changes for the people who sign in
Section titled “What changes for the people who sign in”Nothing changes for them. Turning SSO on adds Log in with SSO to the login page and leaves everything else as it was.
Passwords keep working alongside it unless you set the account’s login method to Exclusive SSO, which is what closes the password route.
Learnient recognises each person by the email address your identity provider sends, so that address must be the one on their user record.
Your identity provider can only sign in people from your own organisation, and only while its provider is active in Learnient. An identity provider connected to a different Learnient organisation cannot sign in anyone from yours, even with a matching email address.
Who single sign-on refuses
Section titled “Who single sign-on refuses”The same rules apply whether somebody starts from Log in with SSO on your login page or opens Learnient straight from your identity provider’s list of apps. Learnient refuses single sign-on for:
- anybody you have archived
- everybody in your organisation, once single sign-on is switched off for the account
They see SSO is not available for this email address - please sign in another way or contact your administrator. Somebody archived while they’re signing in is refused too.
Archiving blocks passwords as well, but the message is different: a person who’s been archived and tries their password sees You have been archived and can no longer sign in - please contact the support team for assistance.
What happens after you save
Section titled “What happens after you save”Nobody is emailed and nobody is signed out. The next time somebody opens your login page the SSO button is there.
What people see when their email address is not in Learnient
Section titled “What people see when their email address is not in Learnient”When your identity provider signs somebody in with an email address that does not match anybody in your organisation, Learnient refuses the sign-in and shows SSO is not available for this email address - please sign in another way or contact your administrator. The same happens if your identity provider sends no email address at all.
On the web the message appears on your organisation’s single sign-on page; in the mobile app it appears on the sign-in screen. It’s the same message as every other single sign-on refusal, so it never reveals whether an address belongs to another organisation.
If you’re testing with an address that is not in Learnient yet, expect exactly that message. Add the person first, then try again.

