Documentation Center

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.

  • Community
  • |
  • Support Portal
  • Home
  • Organizations & End Users
  • End User Portal

Configure the End User Portal for OAuth Sign In or OIDC SSO

Contact Us

If you have questions or want help, please Submit a Request.

Updated at Sep 18, 2026
By Kali Patrick

Table of Contents

Option 1: OAuth Sign In Option 2: OIDC SSO MFA Label Changes When SSO Bypass Is Enabled Turn On Auto Provisioning

Related Docs

  • About the Organization Details Page
  • About the End User Portal
  • Access the End User Portal
  • Work with Portal Users & Permission Groups

Configuring the End User Portal for Single Sign On (SSO) facilitates:

  • Seamless invoice payment: An office manager can click an invoice link and land in the portal, already authenticated via their Microsoft 365 session. No password prompt, no MFA step. Faster payment, less friction.
  • New hire onboarding: A new employee can receive a portal invite and get into the portal using their company credentials on day one. No "set a new password" step, no separate MFA enrollment.
  • Secure remote access: A remote worker can access their office PC through the portal. Their company's IdP verifies their identity, satisfying security requirements without any extra Syncro-specific steps.

You have two options for letting End Users log into the End User Portal with their existing credentials:

  1. OAuth Sign In: This option is best for getting started immediately, with a simple configuration verification. End Users automatically get signed into the End User Portal with their existing Microsoft or Google accounts. You don't need to configure anything per Organization.
  2. OIDC Single Sign-On (SSO): This option is best when you need enterprise-level attribute mapping or automatic user provisioning. You configure this option per Organization against an OIDC-compliant identity provider such as Microsoft Entra ID or Google. Once the Organization has OIDC SSO enabled, OAuth Sign In (option 1) is suppressed. 

Option 1: OAuth Sign In

OAuth Sign In is a built-in login option for the End User Portal. All you have to do is verify one Syncro account setting.

Prerequisites

  • You must be using the New End User Portal.
  • You must have already created a Portal User. (See Work with Portal Users & Permission Groups for instructions.)

Steps

  1. Navigate to Admin > Customers - Preferences.
  2. Check the box for “Enable Portal Login via OAuth.”
  3. Click Save. 

See also: End User Portal Settings.

Result

When they attempt to access the Portal, Microsoft and Google sign-in buttons appear on the End User's login page, alongside the standard email/and password fields and any link options:

When an end user signs in with Microsoft or Google, Syncro matches the email from the OAuth token to an existing Portal User record. 

  • If a match is found, the user is authenticated. 
  • If no match is found, the end user sees a message that no portal account was found and is directed to contact you. No Portal User is created, since auto-provisioning does not apply to OAuth. [So doesn't this imply creating a Portal User is a Prereq, or there are more steps?]

Notes

MFA behaves differently by provider: 

  • For Google sign-in, Syncro checks the AMR claim in the token, a standard field indicating which authentication methods the user completed. If it shows MFA was satisfied at the Google level, Syncro does not prompt for MFA again for that session. If the claim cannot be read or is absent, Syncro enforces its own MFA. 
  • For Microsoft sign-in, Syncro always enforces its own MFA regardless of your settings; the AMR claim is not reliably available in Microsoft's tokens for this kind of sign-in.

Option 2: OIDC SSO

Use this procedure to set up OIDC SSO for an Organization's End User Portal by entering IdP credentials and registering Syncro's URLs in your identity provider.

Prerequisites

You must be using the New End User Portal. If it isn't enabled, attempting to interact with the SSO controls during this process will show an “Enable New End User Portal” window. Contact your administrator if the Enable button is not visible, as this means you do not have appropriate permissions. See Set Up Your Syncro Account for more information.

Steps

  1. In Syncro, navigate to Organizations > [Organization Name] > Organization Details and scroll to the End User Portal section:
  2. Click the “Configure OIDC SSO” link in the upper right to open the “Configure OIDC SSO” pop-up window.
  3. Copy the Redirect URL and the Logout URL.(The Redirect URL may be called a Callback URL in IdP documentation.)
  4. In your IdP, register the Redirect URL and Logout URL. 
  5. Retrieve your Client ID, Client Secret, and Discovery URL. 
  6. Back in Syncro, enter the Client ID, Client Secret, and Discovery URL in the fields:

    Note: Required fields must have values to enable the Save & Test button.
  7. (Optional) Check "Enable OIDC SSO" to activate it immediately. If you want to save your credentials without activating yet, leave the box unchecked. 
  8. Click Save Changes. Or, to save and immediately run a validation test, click Save & Test instead.
  9. (Optional) Turn On Auto Provisioning.

Results

  • Both OIDC SSO and the standard email/password login fields appear on the portal login page simultaneously:

    Some users in an Organization can authenticate via SSO while others use a password, which is useful for Organizations that work with outside contractors who aren't in the primary company directory.
  • The “Enable OIDC SSO” toggle on the Organization's Details Page updates to match the state of the “Enable OIDC SSO” checkbox. If you enable OIDC SSO here, the "Let SSO logins bypass MFA" toggle on the Organization's Details Page is enabled and set to the On position. This means users can also launch Remote Access (Splashtop) sessions without an additional MFA prompt. See also: MFA Label Changes When SSO Bypass Is Enabled.
  • Microsoft and Google buttons are suppressed for that Organization's login page. This is because OIDC takes precedence; you cannot override this.

Notes

  • Values in the “Configure OIDC SSO” pop-up window sent to the backend only when you save. Closing the pop-up window without saving discards all changes. 
  • The "Enable OIDC SSO" toggle turns portal SSO on or off. Its behavior depends on the state of the Organization.
    • If the New End User Portal is NOT enabled for the Organization, clicking the toggle opens an Enable New End User Portal window from which you can Enable, Learn More, or Cancel. The Enable button is hidden if you do not have permission to enable the New Portal. 
    • If the New End User Portal is enabled but no complete SSO configuration has been saved, clicking the toggle opens the Configure OIDC SSO pop-up window.
    • If the New End User Portal is enabled and a complete SSO configuration has been saved, clicking the toggle turns SSO on or off immediately.
  • If OIDC SSO is disabled after being active, the End User Portal falls back to standard email/password login. Users who have never set a Portal User password can use the “Forgot Password” flow to create one.

MFA Label Changes When SSO Bypass Is Enabled

Note: The “Let SSO logins bypass MFA” toggle only affects Option 2: OIDC SSO sessions. It does not control the separate, automatic MFA bypass that can occur for Google sign-in based on Google's own MFA signal.

When "Let SSO logins bypass MFA" is enabled at the Organization level, the MFA label updates in two places.

  • On the Organization Details page in the Portal Users section, the label reads "Require MFA for this User (except in SSO)."
  • On the End User Details page in the End User Portal section, the label reads "Require MFA (except in SSO)."

When "Let SSO logins bypass MFA" is disabled, both labels revert to their standard wording.

Interpreting Test Results

If you clicked Save & Test when configuring Option 2: OIDC SSO, the system saves your configuration and immediately runs a validation flow against your IdP. 

  • If validation is successful, the pop-up window closes and you are returned to the Organization Details page with a success alert.
  • If validation fails, you are stopped inside the SSO flow and will need to correct your configuration before proceeding.

Note: In some cases testing may not be feasible. If you don't have access to a user account already configured in the IdP with valid credentials, you can save and enable SSO, then verify by logging in as an End User.

Here are the messages you may see after saving or closing the “Configure OIDC SSO” pop-up window:

  • IDP configuration saved. This means the configuration saved successfully.
  • IDP configuration saved with invalid Discovery URL. The configuration saved but the Discovery URL could not be validated. SSO may not function correctly until the Discovery URL is corrected. Verify the URL in your IdP before enabling SSO. 
  • IDP configuration could not be saved. The save failed. No changes were applied. Check your connection and try again.
  • IDP configuration changes discarded. You may have closed the pop-up window without saving by clicking Cancel, pressing Esc, or clicking outside the pop-up window. No changes were applied. Reopening the pop-up window will show the last saved configuration.

Turn On Auto Provisioning

Auto-provisioning lets a new End User log into the End User Portal via OIDC SSO for the first time and automatically creates a Portal User account for them. This means you don't need to create or enable that user in advance.

Prerequisites

Auto-provisioning is available for OIDC SSO only; it is not available for Public OAuth. An End User who signs in via Public OAuth with no existing Portal User account sees the no portal account found message and needs to be added manually.

Steps

Follow these steps to turn on auto provisioning.

  1. Navigate to Organizations > [Organization Name] > Organization Details and scroll to the End User Portal section.
  2. Ensure the Enable OIDC SSO toggle is set to the On position.
  3. Toggle the "Enable SSO Auto Provisioning" toggle to the On position. (It is off by default.)

Results

Auto-provisioning only fires when all of the following are true: 

  • the End User authenticates successfully via OIDC SSO, 
  • no Portal User account already exists for that email in your account, 
  • a matching End User record exists for the Organization, and 
  • you have the auto-provisioning toggle enabled for that Organization. 

If any condition is not met, no account is created. If no matching End User and no Portal User exist, the end user sees a message that no portal account was found and is directed to contact you.

When auto-provisioning fires, Syncro creates a Portal User assigned to your system-wide default Portal Permission Group. You can view and manage this user afterward and update the group manually to grant elevated permissions. No new End User record is created.

Because Portal User records are scoped to your account rather than to an individual Organization, auto-provisioning through a second Organization's SSO can behave differently than expected if that End User already has a Portal User record. See Work with Portal Users & Permission Groups for how Portal User scoping works across Organizations.

One platform for IT teams to strengthen security, streamline operations, and scale support.

Syncro All-in-one MSP Software Facebook Syncro All-in-one MSP Software Twitter Syncro All-in-one MSP Software LinkedIn Syncro All-in-one MSP Software YouTube Syncro All-in-one MSP Software Reddit
  • Compliance
  • Privacy Policy
  • Website Terms
  • Service Terms
Knowledge Base Software powered by Helpjuice

© 2017-2026 Syncro Technologies, Inc. All rights reserved.

Expand