SSO launch checklist
Verify company sign-in works, and that access removal works, before you switch your team over.
2 min read
Check these before company sign-in becomes the way your team reaches Studio. A failure here locks out the people who run your campaigns, so test the recovery path as carefully as the normal one.
Test sign-in
- A colleague in scope signs in with their company account and reaches Studio.
- They land with the access their role allows: no more, and not an empty screen.
- Someone who isn't in scope is refused with a message, not stuck in a loop.
- Sign-in works outside the office network, if your team works remotely.
- Sign-in works on a phone, if anyone reviews campaigns on one.
Test access removal
This part is usually assumed and rarely tested, and it's the one an audit asks about.
- Disable a test colleague's company account and check they lose Studio access.
- Check how fast that happens: at once, or when their current session expires.
Test the recovery path
- Check at least one administrator is still on email sign-in, and that email sign-in is still on for your environment.
- Write down who that is and how, somewhere your team can reach without Studio.
- With Entra ID, note when the client secret expires, and plan to send a new one before that date. See Register the application.
Before you switch everyone
- Tell your team what changes, and what the sign-in button looks like now.
- Agree who they contact if sign-in fails on the day.
Where to send a problem
| What's happening | Contact first |
|---|---|
| Sign-in fails for everyone | Your identity team: check the application registration first |
| Sign-in works but the person lands with no access | Your Studio administrator: it's a role assignment, not SSO |
| One person can't sign in, others can | Your Studio administrator first: a Wrong sign-in method or User not found message is fixed in their Studio account. Then your identity team |
| Someone who left still has access | Your identity team: Studio signs them out within 24 hours of being disabled there. Then your Studio administrator, to delete the account |