Skip to main content

How can I have both single-sign-on (SSO) and external users in the one portal?

By using the LOGIN field for each user, you can manage both internal (SSO) and external (non-SSO) users in the same portal.

Written by Joey Halbert

Once your organisation enables single-sign-on (SSO/SAML), you can choose whether all users are automatically redirected to your SSO login page, or whether users see the standard Tribal Habits login page (with an option to log in via SSO). This is controlled by "Enable auto-redirect for SSO login" in Admin → Account → Security → Authentication, and is off by default.


If "Enable auto-redirect for SSO login" is switched on, all users are sent straight to your SSO login page, which can prevent access for any users in your portal who don't use SSO.


In either case, you can use the LOGIN field for each user to manage external users and grant them access to your portal alongside your SSO users.

What is the LOGIN field?

The LOGIN field will appear for all users once SSO is activated in your portal. By default, it will be set to 'Internal'. There are only two choices for this field, which is explained below:

  • Internal. This user is within your SSO environment (e.g. staff, employees). The platform will use SSO for authentication and use SSO-enabled links in all notifications to them. The user will not be prompted to set any password within Tribal Habits.

  • External. This users is outside your SSO environment (e.g. contractors, volunteers). The user will be required to set a password within Tribal Habits, be directed to a special external login URL (see below) and any links in notification emails will also use the external login URL.

In this way, internal users can use SSO while external users can log in with local credentials and avoid being caught up in your SSO process.

This field can be set manually for individual users, or included as a column in a CSV via the Upload People function (with Internal or External in each cell).

NOTE: Users set to 'External' cannot use internal auto-enrol links. Those links will be caught by the SSO login processes and cannot be utilised otherwise.

Filtering your users according to whether they're 'internal' (SSO) or 'external' (non-SSO) users

If you have a combination of SSO and non-SSO users in your portal, you can use the People filter to identify users according to whether they're 'internal' (SSO) or 'external' (non-SSO) users.

Click the People filter (for example, on the People page, reports, and so forth) and for the 'Login' field, change the drop-down from 'Any' to 'Internal' or 'External' depending on which type of users you want to see.

How do external users login?

How external users log in depends on whether "Enable auto-redirect for SSO login" is switched on.

If auto-redirect is on: external users cannot use your standard login page, since all traffic is sent to your SSO provider. Instead, external users must use the dedicated external user login page, located at:

This URL is included in the invitation for external users, and is used to replace all other URLs in any notification emails sent to these users.


If auto-redirect is off (which we generally recommend for portals with a mix of SSO and external users), external users can log in directly from your standard login page using their username and password. If you'd prefer to keep the login page focused on SSO for your majority of users, you can enable "Hide local login fields" in Admin → Account → Brand → Login Page. This hides the username/password fields behind a customisable link (for example, "External Login"), so external users still have a clear, dedicated way to log in without a separate URL, while SSO stays the prominent option for everyone else. See our branding article for details on customising this.

Did this answer your question?