Configure company sign-in
Set up company sign-in, keep sign-in details secure, and test access before requiring it for your organization.
Updated September 11, 2026
In this article
Company sign-in is a separately quoted, one-time setup service that lets your organization require members to use its Microsoft Entra ID or Okta sign-in service before opening the organization in FTE Tree. It can be added to Position Control or Workforce Planning. Google and Microsoft sign-in are included by default and do not require this setup.
FTE Tree must enable setup before an administrator can configure, test, and enforce the provider. Company sign-in confirms the provider account a member used; it does not grant organization membership, roles, permissions, or department access. Provider MFA also remains separate from FTE Tree MFA.
Before you begin
| Activity | Permission and scope required |
|---|---|
| Ask for setup to be enabled | Contact FTE Tree Support through your approved support process. |
| Configure, test, activate, suspend, remove, or enforce company sign-in | Manage sign-in security for the organization. |
Ask your identity administrator to create a web application, which is the secure connection for FTE Tree, in Microsoft Entra ID or Okta. You will need:
- The provider type.
- The exact issuer URL, which identifies your provider environment.
- The client ID, which identifies the FTE Tree connection to your provider.
- The client secret, which is the confidential value that authorizes that connection.
- Permission to add the FTE Tree callback URL, which is the address that receives members after provider sign-in, to the provider application.
FTE Tree accepts Microsoft Entra ID issuer URLs that contain your organization’s unique tenant identifier and end in /v2.0. Shared Microsoft issuer names such as common, organizations, and consumers are not accepted.
FTE Tree accepts standard Okta managed domains ending in .okta.com, .okta-emea.com, or .oktapreview.com. The issuer may use the organization authorization server or an /oauth2/<authorization-server-id> path. If your provider or custom domain is not available on the page, contact Support to discuss available options.
Configure company sign-in
- Ask FTE Tree Support to enable company sign-in setup for your organization.
- Open Settings > Security & sign-in > Company sign-in.
- Select the provider and enter its exact issuer URL and client ID.
- Copy the callback URL shown by FTE Tree into the web application in your provider. It must match exactly.
- Enter the client secret directly in the FTE Tree form. Do not email it, paste it into a support request, or include it in the reason for change.
- Enter a short reason for the setup and choose Validate and save.
FTE Tree checks that the issuer matches the selected provider. The client secret is accepted when you save and is not displayed again. Keep your recoverable copy in your organization’s approved credential manager.
Saving a provider change or a new client secret clears the previous test and turns off enforcement. Complete a new provider sign-in test before requiring company sign-in again.
Test before enforcement
- Keep another working FTE Tree sign-in method and recovery contact available.
- On the Company sign-in page, choose Test company sign-in.
- Sign in with the intended provider account for an active administrator who has the Manage sign-in security permission.
- Confirm that you return to the correct organization and retain the expected FTE Tree role and department access.
- Test additional intended members before enforcement, including administrators and emergency contacts.
- Copy the Company sign-in URL from the page and give it to intended members through a secure channel your organization uses.
A successful sign-in by the eligible administrator records the test automatically. A matching email address, general Microsoft sign-in, provider group, or another provider does not count as the test.
Require company sign-in
Choose Require company sign-in only after the page shows a successful provider test and every intended member is ready.
When enforcement is on, members must use the exact configured provider. A password, email code, general Microsoft or Google sign-in, or FTE Tree authenticator code alone cannot bypass the requirement.
Before enforcement:
- Confirm that every intended member has an account in the provider.
- Keep at least one active organization administrator who can use the provider and has working FTE Tree recovery methods.
- Record who can authorize emergency enforcement changes.
- Review FTE Tree roles and department access separately.
- Confirm who owns provider incidents and member onboarding.
Members use the organization-specific Company sign-in URL. The callback URL is only the return address configured in the provider’s web application; it is not the member sign-in link.
Rotate a client secret
Create a replacement secret at the provider before revoking the current one when the provider supports overlapping secrets.
Open the Company sign-in page, enter the new client secret, record the reason, and choose Validate and save. Leave the provider, issuer, and client ID unchanged for a routine rotation. FTE Tree stores the new value, retires the prior stored value, clears the previous test, and turns off enforcement.
Complete a new real sign-in test. Revoke the old provider secret only after the new test succeeds and your rollback plan is ready, then require company sign-in again if appropriate.
Change or remove a provider
Changing the provider, issuer, or client ID changes how members enter the organization. First stop enforcement, have every affected user remove the old company connection from personal sign-in methods, and confirm no linked company accounts remain. Then save the replacement configuration and complete a new test.
To remove the configuration, suspend company sign-in, remove every linked company account, enter the reason, confirm the removal, and choose Remove configuration. FTE Tree will not remove a configuration while linked accounts remain.
If the provider is unavailable
An authenticator app does not bypass required company sign-in. Restore the provider when possible. A person with the Manage sign-in security permission can stop enforcement or suspend the provider from the Company sign-in page while that administrator still has access.
If no administrator can enter the organization, contact FTE Tree Support with the organization name, provider name, approximate start time, visible error, affected users, and the person authorizing recovery. Never send passwords, sign-in codes, authenticator codes, recovery codes, or provider credentials.
After recovery, activate the provider, complete a new eligible administrator test, and require company sign-in again only after normal and recovery access are confirmed.
Review activity
Use Activity history from the Company sign-in page to review who configured, tested, activated, suspended, enforced, or changed the provider and why. Client secrets are never included in activity.