Configure the End User Portal for OAuth Sign In or OIDC SSO
Table of Contents
Configuring the End User Portal for Single Sign On (SSO) facilitates:
- Seamless invoice payment: An office manager can click an invoice link and land in the portal, already authenticated via their Microsoft 365 session. No password prompt, no MFA step. Faster payment, less friction.
- New hire onboarding: A new employee can receive a portal invite and get into the portal using their company credentials on day one. No "set a new password" step, no separate MFA enrollment.
- Secure remote access: A remote worker can access their office PC through the portal. Their company's IdP verifies their identity, satisfying security requirements without any extra Syncro-specific steps.
You have two options for letting End Users log into the End User Portal with their existing credentials:
- OAuth Sign In: This option is best for getting started immediately, with a simple configuration verification. End Users automatically get signed into the End User Portal with their existing Microsoft or Google accounts. You don't need to configure anything per Organization.
- OIDC Single Sign-On (SSO): This option is best when you need enterprise-level attribute mapping or automatic user provisioning. You configure this option per Organization against an OIDC-compliant identity provider such as Microsoft Entra ID or Google. Once the Organization has OIDC SSO enabled, OAuth Sign In (option 1) is suppressed.
Option 1: OAuth Sign In
OAuth Sign In is a built-in login option for the End User Portal. All you have to do is verify one Syncro account setting.
Prerequisites
- You must be using the New End User Portal.
- You must have already created a Portal User. (See Work with Portal Users & Permission Groups for instructions.)
Steps
- Navigate to Admin > Customers - Preferences.
- Check the box for “Enable Portal Login via OAuth.”
- Click Save.
See also: End User Portal Settings.
Result
When they attempt to access the Portal, Microsoft and Google sign-in buttons appear on the End User's login page, alongside the standard email/and password fields and any link options:

When an end user signs in with Microsoft or Google, Syncro matches the email from the OAuth token to an existing Portal User record.
- If a match is found, the user is authenticated.
- If no match is found, the end user sees a message that no portal account was found and is directed to contact you. No Portal User is created, since auto-provisioning does not apply to OAuth. [So doesn't this imply creating a Portal User is a Prereq, or there are more steps?]
Notes
MFA behaves differently by provider:
- For Google sign-in, Syncro checks the AMR claim in the token, a standard field indicating which authentication methods the user completed. If it shows MFA was satisfied at the Google level, Syncro does not prompt for MFA again for that session. If the claim cannot be read or is absent, Syncro enforces its own MFA.
- For Microsoft sign-in, Syncro always enforces its own MFA regardless of your settings; the AMR claim is not reliably available in Microsoft's tokens for this kind of sign-in.
Option 2: OIDC SSO
Use this procedure to set up OIDC SSO for an Organization's End User Portal by entering IdP credentials and registering Syncro's URLs in your identity provider.
Prerequisites
You must be using the New End User Portal. If it isn't enabled, attempting to interact with the SSO controls during this process will show an “Enable New End User Portal” window. Contact your administrator if the Enable button is not visible, as this means you do not have appropriate permissions. See Set Up Your Syncro Account for more information.
Steps
- In Syncro, navigate to Organizations > [Organization Name] > Organization Details and scroll to the End User Portal section:
- Click the “Configure OIDC SSO” link in the upper right to open the “Configure OIDC SSO” pop-up window.
- Copy the Redirect URL and the Logout URL.(The Redirect URL may be called a Callback URL in IdP documentation.)
- In your IdP, register the Redirect URL and Logout URL.
- Retrieve your Client ID, Client Secret, and Discovery URL.
- Back in Syncro, enter the Client ID, Client Secret, and Discovery URL in the fields:

Note: Required fields must have values to enable the Save & Test button. - (Optional) Check "Enable OIDC SSO" to activate it immediately. If you want to save your credentials without activating yet, leave the box unchecked.
- Click Save Changes. Or, to save and immediately run a validation test, click Save & Test instead.
- (Optional) Turn On Auto Provisioning.
Results
- Both OIDC SSO and the standard email/password login fields appear on the portal login page simultaneously:

Some users in an Organization can authenticate via SSO while others use a password, which is useful for Organizations that work with outside contractors who aren't in the primary company directory. - The “Enable OIDC SSO” toggle on the Organization's Details Page updates to match the state of the “Enable OIDC SSO” checkbox. If you enable OIDC SSO here, the "Let SSO logins bypass MFA" toggle on the Organization's Details Page is enabled and set to the On position. This means users can also launch Remote Access (Splashtop) sessions without an additional MFA prompt. See also: MFA Label Changes When SSO Bypass Is Enabled.
- Microsoft and Google buttons are suppressed for that Organization's login page. This is because OIDC takes precedence; you cannot override this.
Notes
- Values in the “Configure OIDC SSO” pop-up window sent to the backend only when you save. Closing the pop-up window without saving discards all changes.
- The "Enable OIDC SSO" toggle turns portal SSO on or off. Its behavior depends on the state of the Organization.
- If the New End User Portal is NOT enabled for the Organization, clicking the toggle opens an Enable New End User Portal window from which you can Enable, Learn More, or Cancel. The Enable button is hidden if you do not have permission to enable the New Portal.
- If the New End User Portal is enabled but no complete SSO configuration has been saved, clicking the toggle opens the Configure OIDC SSO pop-up window.
- If the New End User Portal is enabled and a complete SSO configuration has been saved, clicking the toggle turns SSO on or off immediately.
- If OIDC SSO is disabled after being active, the End User Portal falls back to standard email/password login. Users who have never set a Portal User password can use the “Forgot Password” flow to create one.
MFA Label Changes When SSO Bypass Is Enabled
Note: The “Let SSO logins bypass MFA” toggle only affects Option 2: OIDC SSO sessions. It does not control the separate, automatic MFA bypass that can occur for Google sign-in based on Google's own MFA signal.
When "Let SSO logins bypass MFA" is enabled at the Organization level, the MFA label updates in two places.
- On the Organization Details page in the Portal Users section, the label reads "Require MFA for this User (except in SSO)."
- On the End User Details page in the End User Portal section, the label reads "Require MFA (except in SSO)."
When "Let SSO logins bypass MFA" is disabled, both labels revert to their standard wording.
Interpreting Test Results
If you clicked Save & Test when configuring Option 2: OIDC SSO, the system saves your configuration and immediately runs a validation flow against your IdP.
- If validation is successful, the pop-up window closes and you are returned to the Organization Details page with a success alert.
- If validation fails, you are stopped inside the SSO flow and will need to correct your configuration before proceeding.
Note: In some cases testing may not be feasible. If you don't have access to a user account already configured in the IdP with valid credentials, you can save and enable SSO, then verify by logging in as an End User.
Here are the messages you may see after saving or closing the “Configure OIDC SSO” pop-up window:
- IDP configuration saved. This means the configuration saved successfully.
- IDP configuration saved with invalid Discovery URL. The configuration saved but the Discovery URL could not be validated. SSO may not function correctly until the Discovery URL is corrected. Verify the URL in your IdP before enabling SSO.
- IDP configuration could not be saved. The save failed. No changes were applied. Check your connection and try again.
- IDP configuration changes discarded. You may have closed the pop-up window without saving by clicking Cancel, pressing Esc, or clicking outside the pop-up window. No changes were applied. Reopening the pop-up window will show the last saved configuration.
Turn On Auto Provisioning
Auto-provisioning lets a new End User log into the End User Portal via OIDC SSO for the first time and automatically creates a Portal User account for them. This means you don't need to create or enable that user in advance.
Prerequisites
Auto-provisioning is available for OIDC SSO only; it is not available for Public OAuth. An End User who signs in via Public OAuth with no existing Portal User account sees the no portal account found message and needs to be added manually.
Steps
Follow these steps to turn on auto provisioning.
- Navigate to Organizations > [Organization Name] > Organization Details and scroll to the End User Portal section.
- Ensure the Enable OIDC SSO toggle is set to the On position.
- Toggle the "Enable SSO Auto Provisioning" toggle to the On position. (It is off by default.)
Results
Auto-provisioning only fires when all of the following are true:
- the End User authenticates successfully via OIDC SSO,
- no Portal User account already exists for that email in your account,
- a matching End User record exists for the Organization, and
- you have the auto-provisioning toggle enabled for that Organization.
If any condition is not met, no account is created. If no matching End User and no Portal User exist, the end user sees a message that no portal account was found and is directed to contact you.
When auto-provisioning fires, Syncro creates a Portal User assigned to your system-wide default Portal Permission Group. You can view and manage this user afterward and update the group manually to grant elevated permissions. No new End User record is created.
Because Portal User records are scoped to your account rather than to an individual Organization, auto-provisioning through a second Organization's SSO can behave differently than expected if that End User already has a Portal User record. See Work with Portal Users & Permission Groups for how Portal User scoping works across Organizations.