Table of contents

Performance & Talent App Initiated Login - SSO

Tom Mullen Updated by Tom Mullen

Following the New User Experience release, all Performance & Talent customers now use OneAdvanced Identity as the authentication service.

The configuration applied to the single sign-on login URL in your Federation provider settings will influence the user experience upon logging in via any apps or mapped URLs.

This article documents the three options Single Sign in Options to Customise your login experience through your Federation app and use of custom sub-domains.

Single Sign On Option 1 - I want my users to login via our existing sub-domain

Configuration requirements

Leave the Single Sign on URL configuration in your Federation provider settings configured to your subdomain URL.

Behaviour

  • After 2nd of March 2026, users going to your subdomain (i.e., https://MyCompany.clearreview.com) will be automatically redirected to https://apps.oneadvanced.com/
  • Users will see the following screen, where they will be prompted to provide their email address.
  • If you have SSO configured they will be redirected to your provider (E.G Entra / Okta / Google ) after they have entered their email address.

Single Sign On Option 2 - I want users to have a seamless SSO login experience without entering an email address when logging in

Configuration requirements

  • Update the Single Sign On URL configuration in your Federation provider settings to map to the following URL:

https://auth.identity.oneadvanced.com/auth/discover?organizationHint=OrgnisationReference&redirectUri=https://apps.oneadvanced.com

Replace OrgnisationReference with your specific Organisation reference.
  • Update any bookmarks and links on your intranet that point to your old sub-domain, with the new mapping.

Behaviour

  • User should go directly to the Single Sign On URL they have mapped, which will allow us to identify which organisation they are accessing the system from.
  • This will mean users are immediately directed to your organisations Federated SSO Login page without the initial email entry prompt.
  • If the user has already authenticated with your provider they will launch straight into Performance & Talent.

If a user still has the old sub-domain bookmarked in their browser, and they navigate directly to the sub-domain (i.e., https://MyCompany.clearreview.com) they will be redirected automatically to https://apps.oneadvanced.com and be prompted for their email address.

How do you retrieve your organisation reference?

  1. You can find your OneAdvanced organisation reference by going to Organisations in the Identity portal.
    Use this link, or find it under Apps on the left menu.
  2. You will be shown a list of the Organisations that you have access to.
  3. Select the Organisation reference for the Organisation that you want to use in your Identity set up.

What field do I need update in my Single Sign On provider?

Azure

The Single Sign on Login URL Field looks like the following in Azure

Okta

The Single Sign on Login URL Field looks like the following in Okta

Google

The Single Sign on Login URL Field looks like the following in Google

Single Sign On Option 3 - I have multiple organisations and want my users to confirm the correct organisation at login, via the new domain

Configuration requirements

  • Update the Single Sign on URL configuration in your Federation provider settings to https://apps.oneadvanced.com
  • Update your bookmarks and intranet links to https://apps.oneadvanced.com

Behaviour

  • Users will not go to your subdomain (i.e., https://MyCompany.clearreview.com) anymore.
  • User should go directly to https://apps.oneadvanced.com/
  • Users will be prompted for their email address at the OneAdvanced login screen.
  • This will allow us to identify their login path.
  • Users will then be redirected to your SSO provider, for example: Entra / Okta / Google.
  • If you have more than one organisation, users will then specify the appropriate organisation.

Was this article useful?

Contact