Single Sign-On (SSO) with Google and Microsoft Entra ID
Esta página aún no está disponible en tu idioma.
Summary Single Sign-On (SSO) lets people from your company sign in to MKController with the account they already use at work — Google Workspace or Microsoft Entra ID (formerly Azure AD). You register your company’s e-mail domains, choose which ways in are allowed for them, and decide what happens when someone new from your domain signs in for the first time.
With SSO, your team uses one work account for everything, nobody shares passwords, and when someone leaves the company, disabling them in Google or Microsoft closes their way into MKController too.
Where to find Single Sign-On
Section titled “Where to find Single Sign-On”Go to Settings → Security → Single Sign-On. The Security menu is only visible to company administrators.
The page has three cards, in the order you set them up: Domains, Ways in and New people.
Step 1 — Register your company’s e-mail domains
Section titled “Step 1 — Register your company’s e-mail domains”- In the Domains card, click the pencil.
- Type your domain — for example company.com. You can also paste a full e-mail address; MKController keeps only the part after the @.
- Click Add.
Every domain starts as Pending approval. MKController checks that the domain really belongs to your company before its rules take effect — until then, nothing changes in sign-in and the Ways in and New people cards stay locked.
| Status | What it means |
|---|---|
| Pending approval | Waiting for MKController’s review. No rule applies yet. |
| Approved | The rules on this page apply to every e-mail on this domain. |
| Rejected | The domain was not accepted. You can remove it and talk to support. |
| Suspended | The rules are paused for this domain. |
Step 2 — Choose the ways in
Section titled “Step 2 — Choose the ways in”Once a domain is approved, choose how people on it can sign in. All three ways in start on:
- Google — Google Workspace accounts from your domain.
- Microsoft (Entra ID) — work accounts from your Microsoft organization.
- E-mail and password — the classic MKController password.
Changes are saved as soon as you flip a switch. At least one way in must stay on.
These rules apply only to people whose e-mail is on an approved domain — everyone else keeps signing in as before.
What people see on the sign-in screen
Section titled “What people see on the sign-in screen”The MKController sign-in screen asks for the e-mail first and then shows only the ways in allowed for that domain. When password sign-in is off, the screen points the person to their company account — and, if something is wrong, to the company administrator.
Step 3 — Decide what happens with new people
Section titled “Step 3 — Decide what happens with new people”When someone from your domain signs in with Google or Microsoft for the first time and has no MKController account yet:
- Approval list (default) — they wait in a queue until an administrator decides their permission and their sites. They receive an e-mail when the account is created.
- Create automatically — they get in immediately, as Analyst on every site, without anyone approving.
Approve access requests
Section titled “Approve access requests”Administrators see “N people waiting for access” in the side menu whenever the queue has someone. You can also open the list from the New people card.
The Access requests page has three tabs:
- Pending — people waiting. Use Create or Ignore.
- Ignored — people you set aside. You can still Create their account later.
- Approved — the history, with the permission and sites granted.
Create opens the Approving user window:
- Choose the permission: Admin, Analyst or Read-only.
- Choose the sites: All (including sites created later) or Custom, ticking the sites one by one. Admins always reach every site.
- Click Save. The account is created and the person gets an e-mail.
Ignore sends no e-mail. If the person tries to sign in again, the request goes back to Pending.
Microsoft Entra ID: what your IT team needs to know
Section titled “Microsoft Entra ID: what your IT team needs to know”- Administrator approval. Many organizations only let an administrator approve third-party apps. If people see “Approval required” when signing in with Microsoft, your Entra ID administrator approves the MKController app once for the whole organization; nobody is asked again after that.
- Your directory, and only yours. The first Microsoft sign-in from an approved domain links that domain to your organization’s Microsoft directory. From then on, only accounts from that directory can sign in with that domain.
- Managed domain. Your domain must be verified in your organization’s Microsoft Entra ID. If Microsoft says the organization is in an unmanaged state, your IT team needs to claim the domain in Microsoft first (a DNS TXT record).
Google Workspace
Section titled “Google Workspace”For an approved domain, Google sign-in only accepts accounts from your Google Workspace — not a personal Google account created with the same address. The first Google sign-in links the domain to your Workspace.
Frequently asked questions
Section titled “Frequently asked questions”Do the rules affect users with other e-mail domains?
Section titled “Do the rules affect users with other e-mail domains?”No. Only people whose e-mail is on one of your approved domains. Partners, contractors and anyone else keep signing in exactly as they do today.
Why is my domain still “Pending approval”?
Section titled “Why is my domain still “Pending approval”?”MKController checks that each domain really belongs to your company before its rules take effect. Until then nothing changes in sign-in. If it is taking long, talk to support.
Someone from my domain can’t sign in. What should I check?
Section titled “Someone from my domain can’t sign in. What should I check?”- The way in they are using (Google, Microsoft or password) is on.
- With Approval list, they may be waiting in Access requests → Pending.
- With Microsoft, your organization may still need to approve the app.
Can I remove a domain?
Section titled “Can I remove a domain?”Yes, in the Domains card. Its rules stop applying immediately, and adding it back requires a new approval.
Next steps
Section titled “Next steps”- Secure remote access links — stop remote access links from being forwarded.
- Active sessions — see who is signed in and revoke access.
Didn’t find what you need? Have questions or feedback? Reach out to MKController Support.
👉 Click here to talk to us.