Single Sign-On (SSO) lets learners log in to Form LMS using their existing organisation credentials, removing the need for a separate username and password after the initial setup.
✅ Before you start: Contact your account manager to purchase and activate SSO. A Me Learning administrator will enable it on your site.
Form LMS supports one or more instances of a SAML 2.0 compliant SSO module. Each instance can connect to a different Identity Provider such as Google Workspace or Microsoft Entra ID (formerly Azure AD).
Setting up SSO
Once the SSO module has been added to your site, setup follows three stages:
- Me Learning shares the data you need for your configuration.
-
You set up the connection in your Identity Provider. See the guides below for help:
- You share the metadata from your Identity Provider with Me Learning, and the setup is completed for you.
Requiring SSO
SSO is optional until you require it. Each workspace has its own setting under Setup → Site settings → Authentication, with three choices:
- Optional: users choose single sign-on or password sign-in. This is the default.
- Everyone: everyone must sign in with SSO, apart from the exceptions you list.
- Specific users: only the email addresses and domains you list must sign in with SSO.
This lets you require SSO for people inside your network while staff outside it keep password sign-in. For the steps, see Require single sign-on for a workspace.
How Form decides who must use SSO
Form checks an email address against your lists in this order:
- The address is listed as an exception. SSO is not required.
- The address's domain is listed as an exception. SSO is not required.
- The requirement is Everyone. SSO is required.
- The address, or its domain, is listed under Required for. SSO is required.
Domains match exactly. A rule for example.com does not cover mail.example.com.
ℹ️ Note: A Site Admin keeps password sign-in for every workspace in their organisation, so a requirement cannot lock them out. An Admin, who looks after a single workspace, is treated like any other user and can lock themselves out. Add an exception for your own address if you cannot sign in with SSO.
What users see
Users enter their email address first. If SSO is required for them, the login screen offers the SSO button only and tells them their organisation requires single sign-on.
For those users, Form also:
- hides Change password and two-factor authentication in My profile → Security
- turns off password reset, including the forgotten password flow and admin-led resets
- skips the set-a-password step when they accept an invitation
- replaces the password fields on self-registration with a Continue with button, provided the workspace has an active SSO method
If a user belongs to more than one workspace, they keep password sign-in for the workspaces that do not require SSO. Opening one that does require it takes them to your organisation's sign-in page, without signing out first.
Where Form cannot work out which sign-in page opens that workspace, it asks them to sign out and sign back in instead.
SSO and 2FA/MFA
Learners can use either SSO or Multi-Factor Authentication (MFA) to log in. These two methods cannot be combined for the same user at the same time. If both are active, SSO takes priority and 2FA/MFA is skipped.
If a learner uses SSO:
- Form redirects them to their organisation's authentication system after validating their email.
- The organisation's security rules and settings apply.
- Any login settings configured in Form (such as 2FA/MFA) are ignored.
What you can do
- Require single sign-on for a workspace
- Setting up single sign-on for Microsoft Entra ID
- Setting up single sign-on for Google Workspace