1. Home
  2. StarShip 101
  3. General
  4. Logging in to Starship Using SSO with Multi-Factor Authentication
  1. Home
  2. StarShip 101
  3. Company
  4. Logging in to Starship Using SSO with Multi-Factor Authentication

Logging in to Starship Using SSO with Multi-Factor Authentication

SSO with MFA

Overview

SSO (Single Sign-On) is a security configuration that forces users to authenticate only through the enabled SSO provider (e.g., Microsoft or Google).

Exclusive SSO

When Exclusive SSO is enabled, the users are authenticated via enabled SSO provider (e.g., Microsoft or Google) and traditional username/password login will be disabled for the users.

Tenant Creation Process

  1. A new tenant is created by either:
    • The Customer (self-registration or onboarding process), or
    • A Professional Service Consultant.
  2. During the tenant setup, the first admin user is created.
  3. This admin user acts as the primary user and controls the SSO settings.

Admin User Email Notification

After tenant creation:

  • The system sends a “Welcome/Login Credentials” email to the admin.
  • This email includes:
    • Login URL
    • Username
    • Temporary password

  • The admin logs in using the provided username and password.
  • Upon login, the admin may be required to update their temporary password
  • After logging in, the admin navigates to Settings → Require users to log in using Single Sign-On (SSO) with the selected service provider->choose the SSO provider from Dropdown
  • Click on Save

Once the admin enables Exclusive SSO setting ON

  • The admin creates the additional users for the tenant
  • Each created user receives an email containing login instructions for SSO.
  • The user follows the SSO login instructions, clicking on the Log in here URL, which lead to a login pop-up.

  • In the pop-up, only the SSO login button (Sign in with SSO Provider) is visible (no username/password fields).

Starship Subscription Management:

Starship Application:

  • The user clicks the SSO button and is redirected to SSO provider Authentication page. Enter the Email address that is linked with SSO Provider and Click “Next”.

  • Enter the password and Click “Sign in”

  • User should complete Multi-Factor Authentication (MFA) by doing one of the following that their organization is registered with:
    • Approve the push notification in the SSO provider Authenticator app, or
    • Enter the 6-digit verification code, or
    • Use an SMS or email code, if allowed.

Example of MFA via Authenticator app:

  • Once the user is successfully authenticated, the system is redirected to the Starship home page.

Normal SSO Flow:

Users could log in using either standard credentials (Username & Password) or Single Sign-On (SSO). This option is available for all users.

User Creation and Login:

When the users are created in a tenant, the following email will be sent where users are either go with standard credentials (Username and Password) or with options to sign in using the preferred SSO provider (Microsoft, Google, etc.).

  • Clicking on the Log in here URL, which lead to a login pop-up.
  • The login pop-up will display standard credentials (Username and Password) along with options to sign in using the preferred SSO provider (Microsoft, Google, etc.).

Starship Subscription Management:

Starship Application:

  • The user clicks the SSO button and is redirected to SSO provider Authentication page. Enter the Email address that is linked with SSO Provider and Click “Next”.

  • Enter the password and Click “Sign in”

  • User should complete Multi-Factor Authentication (MFA) by doing one of the following that their organization is registered with:
    • Approve the push notification in the SSO provider Authenticator app, or
    • Enter the 6-digit verification code, or
    • Use an SMS or email code, if allowed.

Example of MFA via Authenticator app:

  • Once the user is successfully authenticated, the system is redirected to the Starship home page.