Table of contents
- Single Sign On Option 1 - I want my users to login via our existing sub-domain
- Single Sign On Option 2 - I want users to have a seamless SSO login experience without entering an email address when logging in
- Single Sign On Option 3 - I have multiple organisations and want my users to confirm the correct organisation at login, via the new domain
Performance & Talent App Initiated Login - SSO
Updated
by Tom Mullen
- Single Sign On Option 1 - I want my users to login via our existing sub-domain
- Single Sign On Option 2 - I want users to have a seamless SSO login experience without entering an email address when logging in
- Single Sign On Option 3 - I have multiple organisations and want my users to confirm the correct organisation at login, via the new domain
Following the New User Experience release, all Performance & Talent customers now use OneAdvanced Identity as the authentication service.
The configuration applied to the single sign-on login URL in your Federation provider settings will influence the user experience upon logging in via any apps or mapped URLs.
This article documents the three options Single Sign in Options to Customise your login experience through your Federation app and use of custom sub-domains.
Single Sign On Option 1 - I want my users to login via our existing sub-domain
Configuration requirements
Leave the Single Sign on URL configuration in your Federation provider settings configured to your subdomain URL.
Behaviour
- After 2nd of March 2026, users going to your subdomain (i.e., https://MyCompany.clearreview.com) will be automatically redirected to https://apps.oneadvanced.com/
- Users will see the following screen, where they will be prompted to provide their email address.
- If you have SSO configured they will be redirected to your provider (E.G Entra / Okta / Google ) after they have entered their email address.

Single Sign On Option 2 - I want users to have a seamless SSO login experience without entering an email address when logging in
Configuration requirements
- Update the Single Sign On URL configuration in your Federation provider settings to map to the following URL:
https://auth.identity.oneadvanced.com/auth/discover?organizationHint=OrgnisationReference&redirectUri=https://apps.oneadvanced.com
- Update any bookmarks and links on your intranet that point to your old sub-domain, with the new mapping.
Behaviour
- User should go directly to the Single Sign On URL they have mapped, which will allow us to identify which organisation they are accessing the system from.
- This will mean users are immediately directed to your organisations Federated SSO Login page without the initial email entry prompt.
- If the user has already authenticated with your provider they will launch straight into Performance & Talent.

How do you retrieve your organisation reference?
- You can find your OneAdvanced organisation reference by going to Organisations in the Identity portal.
Use this link, or find it under Apps on the left menu. - You will be shown a list of the Organisations that you have access to.
- Select the Organisation reference for the Organisation that you want to use in your Identity set up.

What field do I need update in my Single Sign On provider?
Azure
The Single Sign on Login URL Field looks like the following in Azure

Okta
The Single Sign on Login URL Field looks like the following in Okta

The Single Sign on Login URL Field looks like the following in Google

Single Sign On Option 3 - I have multiple organisations and want my users to confirm the correct organisation at login, via the new domain
Configuration requirements
- Update the Single Sign on URL configuration in your Federation provider settings to https://apps.oneadvanced.com
- Update your bookmarks and intranet links to https://apps.oneadvanced.com
Behaviour
- Users will not go to your subdomain (i.e., https://MyCompany.clearreview.com) anymore.
- User should go directly to https://apps.oneadvanced.com/
- Users will be prompted for their email address at the OneAdvanced login screen.
- This will allow us to identify their login path.
- Users will then be redirected to your SSO provider, for example: Entra / Okta / Google.
- If you have more than one organisation, users will then specify the appropriate organisation.

