ActiveManage Docs ← Back to activemanage.co.uk

External Sign-in Sources

As well as its own accounts, ActiveManage can sign users in against external identity sources. Each appears as a tile on the login page once you have entered its credentials and switched it on.

What is available

  • Active Directory — on-premises corporate sign-in.
  • Azure AD / Microsoft Entra ID — Microsoft 365 organisations.
  • SAML 2.0 — enterprise single sign-on with Okta, Auth0, ADFS, Google Workspace and others.
  • Windows Integrated Authentication — domain users signed in with no prompt at all.
  • Google, Microsoft, Apple, Amazon, GitHub, Facebook, Instagram, LinkedIn — consumer and public-facing sign-in.
  • Xero — sign-in for accounting users.
  • Login Links — a one-time link e-mailed to the user, with no password at all.
  • Another ActiveManage instance — federating two installations.

Where to configure them

Architect Panel → Security → Authentication Methods. Each source is listed with its own credential fields and an on/off switch. SAML providers, Azure tenants, Google registrations and Xero connections each have their own record holding the detail of each connection.

Everything arrives switched off

Every external source is supplied disabled with no credentials. Nothing appears on your login page until you configure it deliberately.

How external users are identified

ActiveManage identifies an external user by the identifier their provider issues, not by their e-mail address, and records which connection they came through. That matters because e-mail addresses change and are not unique across organisations, whereas the provider's identifier is stable. It also means two different providers cannot collide into one account.

Worked Examples

  • B2B SaaS: SAML for enterprise customers, Google and Microsoft for smaller ones.
  • Internal system: Windows Integrated Authentication on the corporate network, Azure AD off it.
  • Consumer marketplace: Google, Apple and Facebook, with ActiveManage accounts as the fallback.