> For the complete documentation index, see [llms.txt](https://docs.itoc360.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.itoc360.com/users-and-access-management/single-sign-on-sso.md).

# Single sign-on / SSO

ITOC360 supports single sign-on (SSO) with three identity providers: **Google**, **Microsoft**, and **Slack**.

SSO removes the need to manage a separate ITOC360 password. You can use it to create a brand-new account or to sign in to an account you already have.

| Provider  | Sign up | Sign in | Web | Mobile |
| --------- | ------- | ------- | --- | ------ |
| Google    | Yes     | Yes     | Yes | Yes    |
| Microsoft | Yes     | Yes     | Yes | Yes    |
| Slack     | Yes     | Yes     | Yes | Yes    |

> **One account, one identity.** ITOC360 matches SSO logins by email address. If an ITOC360 account already exists with the email address returned by your provider, that account is used — a duplicate account is never created. See **Account linking** below.

### Before you begin

* You need an active Google, Microsoft (personal or work/school), or Slack account.
* Any email domain is accepted. A corporate or educational address is not required — personal addresses such as `name@gmail.com` work exactly the same way. Only addresses from known spam or disposable domains are rejected.
* For Slack, you must be a member of at least one Slack workspace. Slack requires a workspace to be selected during authorization; this is Slack's own behaviour and cannot be skipped.

### Signing up with SSO (Web)

Use this flow if you do not have an ITOC360 account yet.

1. Go to the ITOC360 sign-in page and click **Sign up**.
2. Under **OR CONTINUE WITH**, choose **Continue with Google**, **Continue with Microsoft**, or **Continue with Slack**.
3. Complete the provider's authorization screen. See **Provider-specific screens** below.
4. You are returned to ITOC360 and the onboarding flow starts, because a new SSO user does not belong to an organization yet.
5. Follow onboarding to create your organization, then continue to the **Quickstart Guide**.

> **Note:** If an ITOC360 account already exists with the same email address, you are not taken to onboarding. You are signed in to the existing account instead, and the provider is linked to it.

<figure><img src="/files/vViPRLTyLBG7eWbH5Jyh" alt=""><figcaption></figcaption></figure>

### Signing in with SSO (Web)

1. Go to the ITOC360 sign-in page.
2. Click **Continue with Google**, **Continue with Microsoft**, or **Continue with Slack**.
3. Select your account on the provider's screen and approve access.
4. You are returned to ITOC360 and land on your dashboard.

If two-factor authentication is enabled on your account, you are still prompted for your MFA code after the SSO step. See **SSO and MFA** below.

<figure><img src="/files/cjwqayVYN4FzbDMTxgNR" alt=""><figcaption></figcaption></figure>

### Provider-specific screens

#### Google

Google opens `accounts.google.com` with a **Choose an account** list showing every Google account signed in on the device, under the heading *Continue to ITOC360*.

1. Select the account you want to use.
2. If the account has never authorized ITOC360, approve the consent screen.

Accounts marked as signed out require you to enter your Google password first.

<figure><img src="/files/bmY8NMaRYprvCUIzcD5b" alt="" width="563"><figcaption></figcaption></figure>

#### Microsoft

Microsoft opens `login.microsoftonline.com` with a **Pick an account** list.

1. Choose your account, or select **Use another account** to sign in with a different one.
2. Approve the permissions request if this is your first time.

Both personal Microsoft accounts and work/school (Entra ID) accounts are supported. Work/school accounts may additionally require your tenant administrator to consent to the ITOC360 application.

<figure><img src="/files/37yYvHCoXqTpcrkKkRCr" alt="" width="563"><figcaption></figcaption></figure>

#### Slack

Slack opens **Sign in to ITOC360 with Slack**, where you select a Slack account or workspace.

The consent screen explains that your Slack account details are used to establish a verified connection between an existing ITOC360 account and Slack, to create a new ITOC360 account if you do not have one, and to enable ITOC360 features inside Slack such as configurable notifications, rich link previews, and quick actions. Slack shares your name, email address, profile image, user ID, and team ID with ITOC360.

1. Select the workspace you want to authorize. Workspace selection is mandatory — Slack does not offer a workspace-free login.
2. Click **Accept and Continue**.

<figure><img src="/files/mbdJ21YLDV7iM95FQbbo" alt="" width="563"><figcaption></figcaption></figure>

### Signing in with SSO (Mobile)

The ITOC360 mobile app uses the same accounts and the same backend as the web app. Any account that works on the web works on mobile, and vice versa.

1. Open the ITOC360 app and go to the **Welcome back** screen.
2. Below the **OR** divider, tap the **Google**, **Microsoft**, or **Slack** icon.
3. The provider's page opens in an in-app browser (`accounts.google.com`, `login.microsoftonline.com`, or `itoc360.slack.com`).
4. Select your account and approve access.
5. The browser closes and you are signed in.

*Mobile sign-in screen. The three SSO providers appear as icons below the **OR** divider.*

> **Note:** The mobile app shows sign-in buttons only — there is no separate mobile sign-up screen. Create your account and organization once on the web, then sign in on mobile with the same provider.

For everything else about the app, see **Getting started with the ITOC360 mobile app**.

<figure><img src="/files/FjAMU7b9dMgng72sWPOh" alt="" width="563"><figcaption></figcaption></figure>

### Account linking

ITOC360 identifies you by the email address your provider returns.

* **If that email address already belongs to an ITOC360 user**, the provider is linked to that existing user. You are signed in to your current account with your organization, teams, schedules, and escalation policies intact. No second account is created and no data is duplicated.
* **If the email address is not in use**, a new user is created and onboarding starts so you can set up an organization.

Linking happens in one of two ways:

* **Automatically**, the first time you sign in with a provider whose email address matches an existing ITOC360 user.
* **Manually**, from **Account → Security → Connected accounts**, at any time. See **Managing connected accounts** below.

#### Your existing password keeps working

Linking a provider does not disable password login. Once Google is linked to a password-based account, both methods remain valid — sign in with the provider or with your email and password, whichever is convenient.

#### Every provider can be linked to the same account

All three providers match on email address, so they can all point at one ITOC360 user. If your account was created with Google and you later click **Continue with Slack** while your Slack account uses the same email address, you are signed in to the same ITOC360 user. Nothing is duplicated and nothing needs to be merged afterwards.

In practice a single account can be reached four ways: email and password, Google, Microsoft, and Slack — as long as the email address is the same everywhere.

#### Example

Your ITOC360 account is `johndoe@example.com`, created with an email and password. You click **Continue with Google** and pick your `johndoe@example.com` Google account. ITOC360 recognizes the address, links Google to your existing user, and signs you in — same account, same organization, same password as before.

### Managing connected accounts

You do not have to wait until your next sign-in to link a provider. Linked sign-in methods are listed and managed under your account settings.

1. Open **Account** from the sidebar.
2. Switch to the **Security** tab.
3. Scroll to **Connected accounts**.

Each provider is listed with its current state. Providers that are not yet linked show **Not connected** with a **Connect** button.

<figure><img src="/files/95B8z1fXl8StVPVTUfMy" alt=""><figcaption></figcaption></figure>

***Account → Security → Connected accounts.** Sign-in methods linked to your account.*

#### Connecting a provider

1. Click **Connect** next to the provider you want to add.
2. Complete the provider's authorization screen.
3. You are returned to the **Security** tab and the provider is shown as connected.

From that point on, the provider's button on the sign-in page takes you straight into this account.

> **Note:** The same **Security** tab also holds **Change Password**, **Multi-factor (SMS)**, and **Multi-factor (TOTP)**. Adding an SSO provider does not affect either MFA method. See **Two-factor authentication / MFA**.

### Setting a password for an SSO account

If your account was created through SSO and you also want to sign in with an email and password:

1. On the sign-in page, click **Forgot password?**
2. Enter the email address associated with your SSO account.
3. Open the reset link sent to that address and choose a password.

You can then use either method to sign in.

### SSO and MFA

SSO does not replace ITOC360's two-factor authentication. If MFA is enabled on your account, you are prompted for your authenticator or SMS code after the provider returns you to ITOC360.

To enable, change, or recover MFA, see **Two-factor authentication / MFA**.

### Troubleshooting

| Symptom                                                                 | Cause                                                                                                       | What to do                                                                                                                                    |
| ----------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------- |
| Signed in but landed on onboarding unexpectedly                         | The provider returned an email address that is not attached to any ITOC360 user, so a new user was created. | Sign out of the provider and retry with the account whose address matches your ITOC360 user. Contact Support if a duplicate user was created. |
| Sign-up rejected with an email error                                    | The address belongs to a domain blocked as spam or disposable.                                              | Use a different address. Any regular personal, corporate, or educational domain is accepted.                                                  |
| Microsoft returns a consent or admin-approval error                     | Your work/school tenant requires administrator consent for third-party applications.                        | Ask your Microsoft tenant administrator to approve ITOC360, or sign in with a personal Microsoft account.                                     |
| Slack asks for a workspace and you have none                            | Slack authorization always requires a workspace.                                                            | Join or create a Slack workspace, or use Google or Microsoft instead.                                                                         |
| Provider page does not close on mobile                                  | The in-app browser lost the callback.                                                                       | Close the browser sheet, return to the app, and tap the provider icon again.                                                                  |
| Cannot find where to manage linked providers                            | The list is on the **Security** tab, not the **Profile** tab.                                               | Go to **Account → Security → Connected accounts**.                                                                                            |
| Provider shows **Not connected** even though you have signed in with it | The provider returned a different email address, so it was linked to a different ITOC360 user.              | Click **Connect** on this account to link it explicitly, then contact Support about the duplicate user.                                       |
| Still prompted for a code after SSO                                     | Expected behaviour — MFA is enabled on the account.                                                         | Enter your MFA code. See **Two-factor authentication / MFA**.                                                                                 |

Anything not covered here: **Contacting Support**.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.itoc360.com/users-and-access-management/single-sign-on-sso.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
