SSO FAQ
Answers about SAML compatibility, user provisioning, identity platforms and SSO projects.
Frequently asked questions
Compatibility and authentication
Which SSO protocol does Goodays support?
Goodays supports SAML v2 as its standard SSO protocol. OpenID Connect and OAuth alone are not supported as standard alternatives, but a feasibility request can be submitted to Goodays to assess whether an alternative protocol can be used for a specific project.
Can we use Microsoft Entra ID, Okta or Ping Identity?
Yes, provided your platform is configured to act as a SAML v2 Identity Provider and can supply the information required for the selected SSO model.
Is SSO the same as JWT authentication?
No. SAML SSO delegates employee authentication to your corporate Identity Provider. Goodays is also compatible with JWT for token-based journeys initiated by another application, but this requires a dedicated workshop and is handled outside the SSO project.
Accounts and provisioning
Does SSO automatically create Goodays accounts?
It depends on the selected model:
- Static SSO: the account must already exist in Goodays before the first SSO login.
- Dynamic SSO: Goodays can create and update the account according to the attribute contract approved for the project.
What identifier should our IdP send?
For both Static SSO and Dynamic SSO, Goodays uses the professional email address as the unique user identifier. With Static SSO, it must match the existing Goodays account. With Dynamic SSO, additional attributes may be sent for the profile, role and access scope, but the user is still identified by email.
When are Dynamic SSO changes applied?
The approved provisioning rules are evaluated when the user successfully logs in.
Is Dynamic SSO the same as directory synchronization or SCIM?
No. Goodays Dynamic SSO uses approved SAML attributes during authentication. It is not a continuous directory-synchronization or generic SCIM service.
Who owns the quality of provisioning attributes?
Your organization owns the source data and the meaning of the values sent by the IdP. Goodays validates the agreed mapping and applies the approved provisioning behavior.
Dynamic SSO project
Is Dynamic SSO available as a standard option?
No. Dynamic SSO is a tailored provisioning project, not a turnkey setting. It requires a preliminary workshop followed by a Goodays feasibility review and explicit validation before implementation.
Why does Dynamic SSO require a workshop?
Corporate identity models are different. The same role or organizational concept may use different names, reference systems and lifecycle rules from one company to another. The workshop determines whether the available data can reliably produce the expected Goodays access.
Domains, organizations and lifecycle
Can several subsidiaries use different IdPs?
Yes. Several SSO configurations can coexist for the same organization. Each email domain can be linked to one SSO configuration only, while one SSO configuration and IdP can be linked to several email domains. Share the complete domain and organization structure during scoping so that Goodays can confirm the routing design.
What if our users have public email domains?
Goodays cannot use a public domain such as gmail.com to redirect users to a specific client's IdP. However, your IdP can initiate SAML authentication toward Goodays from your own corporate portal, intranet or application tile. In that journey, users start from your environment rather than from the Goodays login page.
Can SSO and another login method coexist?
Different populations may use different login journeys. The exact scope and rollout behavior are agreed with Goodays based on the relevant domains and user groups.
What happens when our SAML certificate changes?
Your identity team should provide updated metadata to Goodays through the agreed channel before the current certificate expires. Both teams coordinate the configuration update.
Who should we contact to start?
Contact your Goodays representative with your IdP, the relevant domains and user populations, and your expected account-management model. For Dynamic SSO, include the business and identity contacts who can participate in the preliminary workshop.
Updated 1 day ago
What’s Next
Contact Goodays to confirm the SSO design that fits your organization.