When employees have separate passwords for every tool — email, HR, payroll, project management — they either forget them, reuse them, or store them insecurely. Single Sign-On (SSO) eliminates this by letting employees sign in to Leave Balance using the same credentials they use for email and other work apps. One login, one less password, and better security for employee data.
SSO for HR tools matters more than SSO for most other apps. Leave systems contain personal data — dates of absence, medical information, salary details. Protecting access to that data with enterprise-grade authentication is not a luxury. It is a baseline requirement for any business with more than 20 employees.
Key Takeaways
- SSO lets employees sign in to Leave Balance using their existing company credentials
- SAML 2.0 is the standard protocol for connecting HR tools to identity providers like Okta, Azure AD, and Google Workspace
- Setup involves configuring your identity provider and connecting it to Leave Balance in about 20 minutes
Why SSO Matters for HR Software
HR tools hold some of the most sensitive data in any organisation: personal information, salary details, medical leave records, and disciplinary information. If an employee’s HR tool password is weak or reused across other services, a breach of any of those services could expose HR data.
SSO addresses this by centralising authentication. Instead of managing passwords for each tool, employees authenticate once with the identity provider (IdP) and receive access to all connected applications. The benefits:
- Stronger security. The identity provider enforces password policies, MFA, and session management. Individual tools inherit these controls.
- Fewer support tickets. Password resets are the single most common IT support request. SSO eliminates the need for separate HR tool passwords.
- Better audit trails. Identity providers log who signed in, when, and from where. This provides a centralised access log for compliance.
- Faster onboarding. New employees get access to Leave Balance through their existing account. No separate HR tool account to create.
How to Set Up SSO for Leave Balance
Step 1: Confirm Your Plan Supports SSO
SSO is available on Leave Balance plans that include team administration features. Check your plan’s feature list or contact support to confirm SSO availability.
Step 2: Choose Your Identity Provider
Leave Balance supports SAML 2.0, which is the standard protocol used by all major identity providers:
| Identity Provider | SAML Support |
|---|---|
| Okta | Yes |
| Azure Active Directory (Entra ID) | Yes |
| Google Workspace | Yes (via SAML) |
| OneLogin | Yes |
| PingIdentity | Yes |
| Auth0 | Yes (as SAML IdP) |
If your organisation uses any of these providers, you can connect Leave Balance without additional configuration.
Step 3: Get Your SAML Configuration Details
In your Leave Balance account, navigate to Settings > Security > SSO Configuration. You will see:
- Entity ID / Audience URI: The unique identifier for your Leave Balance workspace
- ACS URL (Assertion Consumer Service URL): Where your identity provider sends the SAML response
- Certificate: The public certificate Leave Balance uses to verify SAML assertions
Copy these values into your identity provider’s SAML configuration.
Step 4: Configure Your Identity Provider
In your identity provider’s admin console, create a new SAML application:
-
Enter the Entity ID and ACS URL from Leave Balance
-
Upload the Leave Balance certificate
-
Map the required user attributes:
- Email address (required) — must match the employee’s email in Leave Balance
- First name (required)
- Last name (required)
- Employee ID (optional) — for additional matching
-
Assign the application to the relevant user groups or organisational units
Step 5: Test the Connection
From your identity provider, initiate a test login to Leave Balance. Verify that:
- You are redirected to your identity provider for authentication
- After successful authentication, you are redirected back to Leave Balance
- Your account is matched to the correct employee profile
- You have the correct permissions based on your Leave Balance role
Step 6: Enforce SSO for Your Team
Once testing is complete, enable SSO enforcement in Leave Balance. This requires all team members to authenticate through the identity provider. Password-based login is disabled for enforced users.
Keep a fallback administrator account with password login in case the identity provider is unavailable.
What Data Flows During SAML Authentication
| Data | Direction | Purpose |
|---|---|---|
| SAML assertion (email, name) | IdP → Leave Balance | Authentication and user matching |
| Session token | Leave Balance → Browser | Maintains login session |
| Access metadata | Leave Balance → IdP | Audit logging of access events |
Best Practices
- Enforce MFA at the identity provider. Leave Balance inherits the MFA policy from your IdP. Enable MFA for all users in the IdP to protect HR data.
- Keep a break-glass admin account. If the IdP goes down, you still need access to Leave Balance. Create a separate admin account with password authentication as a fallback.
- Map users by email. The email address in the SAML assertion must match the employee’s email in Leave Balance. Inconsistent emails cause login failures.
- Review access quarterly. Use your IdP’s audit logs to review who has access to Leave Balance. Remove access for terminated employees immediately.
- Test SSO before enforcing it. Run SSO in audit mode (allow both SSO and password login) for a week before enforcing. This catches configuration issues without locking anyone out.
FAQ
What happens if the identity provider is down?
If the IdP is unavailable, SSO login will fail. This is why we recommend keeping a break-glass admin account with password authentication. If your IdP has SLA guarantees, check that they cover the authentication paths your team uses.
Can I use SSO with just a few employees?
SSO is available on any plan that supports it, regardless of team size. For small teams, the main benefit is convenience — employees do not manage a separate password. For larger teams, the security and compliance benefits are the primary driver.
Does SSO support MFA?
SSO delegates MFA to your identity provider. If your IdP enforces MFA, all Leave Balance logins will require MFA. Leave Balance does not manage MFA separately when SSO is enabled.
Can I disable SSO if it is not working?
Yes. You can disable SSO enforcement in Leave Balance settings at any time. This re-enables password-based login. Keep your break-glass account active in case you need to access the settings while SSO is disabled.
Does SSO work with the Leave Balance mobile app?
Yes. The Leave Balance mobile app supports SSO login. The app opens a browser window for identity provider authentication and then returns to the app after successful login.
leave emails? Track your employee's leave with Leave Balance

