About SSO for your team
Let the people who build campaigns sign in to Studio with the company account they already use.
With single sign-on (SSO), your colleagues select one button on Studio's sign-in page, and there's no separate password to manage. Your IT team sets it up once with OmniLab, and it then applies to everyone in scope.
A colleague opens Studio
They choose sign in with your company account
Your identity system checks who they are
The same screen and rules as your other business tools.
It confirms their identity to OmniLab
OmniLab opens with the access their role allows
Someone who has left the company is stopped at step 3, without anyone touching OmniLab.
A colleague opens Studio
They choose sign in with your company account
Your identity system checks who they are
The same screen and rules as your other business tools.
It confirms their identity to OmniLab
OmniLab opens with the access their role allows
OmniLab never sees a password. It asks your identity system who this is, and trusts the answer.
Why use it
- No separate password for your team to manage or reset.
- Access follows your company identity system. Once someone's company account is disabled, they can't sign in again. An open session ends within 24 hours.
- The same sign-in your team expects from other business tools.
How it's set up
Your IT team registers OmniLab as a trusted application in your company identity provider, such as Microsoft Entra ID or Salesforce. They send a few technical details to your Customer Success Manager, who turns on SSO for your environment.
- Ask your IT team which provider you use: Microsoft Entra ID, Salesforce Marketing Cloud or another.
- Ask your IT team to register OmniLab, following Connect your identity provider.
- Send the details they collect to your Customer Success Manager.
- Check each colleague has a Studio account in at least one organisation.
- Have an Admin set each colleague's Authentication Provider to your company provider.
- Test with two or three colleagues before you move everyone.
Sign-in only works for accounts that already exist. Each account signs in one way only. A colleague still set to email sign-in is refused with Wrong sign-in method, even once their company account signs them in.
When you test, check the sign-in button appears, the provider signs people in, and they land in the right organisation.