Login - Enable Microsoft Entra ID Single Sign On
Ability to use Azure Active Directory for MFA.
Purpose: It makes Microsoft users easily log into Xero.
Hi everyone, we appreciate all the feedback and votes on this idea. We know using Microsoft Entra ID SSO is now common practice for some businesses and being able to access Xero via a native integration with Entra ID would streamline how your teams log in and get set up in Xero, as well as help in managing access for larger teams and keeping things secure.
Our product team have been working with a small limited group of Partners to develop SSO capabilities. Though we can't give any definite timelines yet, we’ll keep this thread updated with news. Thanks
-
Joshua Street
commented
Imagine launching Ultra without fixing this. Which customers need ERP yet pay so little attention to such basic controls when evaluating it?
-
James Bonifield
commented
Consider this as a data point: I am moving to QBO on Sept 1, 2026 if there is not clear indication and prioritization from the product team. I’ll be back to post about this on this date, as it seems almost certain Xero will continue to prioritize shiny objects over user security. It’s embarrassing that you haven’t built this capability which is frankly, really not that hard to do. You don’t even need to build a connector with Entra or Okta, just a page to generate SAML metadata and support self service federation setup. That’s Claude code max + a week of adult supervision + regression testing.
Xero - if you read this - email me at James@apivant.io and I will have my team build the connectors for Okta and Entra for you. I’m not joking. You just have to do the self service SSO set up and metadata exchange piece. I’d be happy to help you build this foundational feature which is a bare minimum for enterprise software.
Also - I strongly agree with Andrew’s point below - it’s a great idea to build out connectors for popular IDPs, but you must support SAML or OIDC generically.
James Bonifield
CEO & Founder, Apivant -
Richard Crozier
commented
I think it's unfair to criticise Xero here, it's only been asked for for 12 YEARS. Well, ok, actually a few more years than that, because there was another SSO idea on here before that which they said they wouldn't do and closed it. Clearly though Xero just had the foresight to see that soon AI was coming and some guy on his own would be able to replicate Xero with Claude Code in a few days, but with SSO, so what's the point of spending ages developing features when you should just milk what you have while you can? This will be my last comment on this issue, I think my 12-15 year journey of following progress on SSO at Xero is coming to an end and I'm going to try and unsubscribe from updates to this idea. So goodbye fellow SSO hopefuls. Maybe I'll check back in every decade or so to see how the feature is coming along. For those of you still waiting, perhaps just starting out on your Xero SSO journey, I wish you well, and godspeed. Think of the future years you wait for this feature as a type of meditative contemplation, a time when you can consider the nature of hope and how it relates to a world in which some thing remain forever out of reach. You can come to learn the true acceptance of things as they are, and not as you wish them to be. In this case, that thing being logging into your flippin Xero account with SSO.
-
Nicholas Piasecki
commented
Can you ask JAX to implement it for you?
-
Mike Baptiste
commented
This is reaching a ridiculous point. Even some of our smaller products in our stack support Google and M365 SSO. Plus the need to constantly log back in every hour is REALLY a pain for users. SSO would at least make it a little smoother. Even better would be passkeys. This is all standard stuff - you aren't having to reinvent the wheel here.
-
Ben Jemison
commented
Could we at least have an update on this please @kelly-munro ? How can this have been in development since October 2025? If that's the case then I'm seriously worried about Xero's technical capabilities to support our business needs going forward. This is not complicated - it's standard stuff for enterprise software to support.
-
Chris Michalski
commented
The lack of OIDC + SCIM is becoming a real problem. Xero is becoming isolated from the rest of our ecosystem, it needs to be sorted.
-
Edward Raine
commented
Modern conditional access via entra is a basic requirement these days, it also guides which SAAS products are purchased by a large part of my customer base. I am shocked Xero doesn't support this yet.
-
Danial Saleem
commented
Really surprised to see this is still pending. SAML and SCIM for any SaaS is no brainer, and this must be implemented ASAP so we can leverage modern auth along with conditional access controls
-
Helen Gerling
commented
Come on Xero - this is ancient technology now. If you'd like some help to get it setup so that anyone can use any OAuth / SAML IdP (including Entra) for authenticating, just get in touch. We set this up for ISVs all the time. and as Xero users ourselves we have a vested interest in solving this.
-
Gavriel Ingram
commented
I'm beyond shocked that this hasn't already been implemented.
The date on this 'idea' is 13 years ago and has receive significant numbers of votes, and where is the progress?
The most recent Xero response (almost a year ago) is sadly weak and non-committal.
We have only just started with Xero, but browsing through this ideas forum is fairly depressing and we are beginning to think we've made the wrong move. -
Thad Legg
commented
It's genuinely disappointing that this has sat as a feature request for over a decade with no real progress for a company the size of Xero, serving businesses that take security seriously, that's hard to justify. Passwordless is where the entire industry has been heading for years now. Microsoft, Google, NIST, and virtually every major security vendor actively recommend passwordless authentication (FIDO2/passkeys, federated identity) over passwords, because passwords remain the single biggest attack surface for credential theft, phishing, and reuse. Still relying on a standalone Xero password, even with MFA bolted on, is already behind where the industry has moved. Native Entra ID/SAML SSO would be a first step, but Xero should be aiming at passwordless as the real end goal, not just SSO as a checkbox. At this point it's not a hard technical problem it's a prioritization failure, and one that's costing Xero credibility with the exact customers it should want to keep.
-
Ben Jemison
commented
This is not a difficult feature to implement from a technical point of view. SAML sign-in options should be offered as standard by providers these days. The fact that Xero haven't yet managed this is astonishing.
-
Ciaran O Brien
commented
Is there any update on this?
-
Jamie Wheeldon
commented
Hi Kelly - any update yet on this idea? It's been well over 9 months now with no updates.
I know this is a non-trivial feature so not expecting you to announce imminent delivery dates or anything, but you did promise updates on your last message.
I think even a simple acknowledgement that this hasn't been forgotten and is still being worked on would be appreciated by alot of the customers following this idea.
-
John Cullen
commented
Is there an update on this from the Dev team? Surely there has been some movement on this since October 2025?
We would love to see the implementation of SAML SSO in Xero so that all businesses can secure and centrally manage their accounts but even if we had Entra/365 that would be a very big tick security wise for a large portion of customers.
-
Andrew Anderson
commented
I think we all want to see SAML SSO available as soon as is reasonable, but "adopting a professional identity provider" is the exact opposite of what is needed. Instead of calling for Xero to dictate that companies use a specific Identity Provider (IdP) platform (365/Entra), the goal should be to support SAML SSO authentication from _ANY_ SAML authentication provider (Microsoft Entra/ADFS, Google, Okta, Auth0, OneLogin, etc). I will be severely disappointed if this feature is launched and only works for Entra.
Also, the SSO standards already exist (https://www.oasis-open.org/standard/saml/), so what is actually needed here is time for the development team incorporate robust eternal authentication feature support into the product.
As for MFA, Xero already supports TOTP-based MFA, and I use it every time I login, so allow me to point you to the MFA setup instructions for Xero that is available today: https://central.xero.com/s/article/Set-up-multi-factor-authentication
For everyone who is berating Xero as "I can't believe in 202x that...", remember that Stripe only rolled out SAML support a year or so ago themselves, so Xero really is not that far behind other SMB financial service providers in supporting 3rd party authentication services. Keep in mind, Intuit does not support native SAML SSO for QBO today, nor does Sage 50 support SAML SSO. You might be thinking about Sage Intacct, but I see that platform occupying a different part of the marketplace at a different price point, and not directly comparable.
The only "support" for QBO is HTML forms stuffing (aka "Forms-based auth" or "SWA" depending on the IdP terminology), so the main competitor in the small business accounting space (Intuit) does not support SAML SSO either. To the best of my knowledge Intuit has not announced plans to support SAML for QBO, so Xero is already ahead of the curve here among its peers.
What I am hoping to see is that Xero is taking the time to do this implementation correctly and that they are following Stripe's example where they allow users and roles to be completely defined in the IdP system and communicated to Stripe (as the Service Provider [SP]) upon every login (https://docs.stripe.com/get-started/account/sso). Under Stripe's design, user permissions are managed centrally at the IdP and access rights are assigned to the user account in the IdP. This is not a trivial change, and is going to take time to implement all of the necessary hooks for this to work correctly.
Xero has already stated that they are working on this barely over 6 months ago. I would rather they take their time and get this implementation right than to rush the implementation to end users and launch a half-baked product. Stripe worked on SSO for 2-3 years before they made it generally available, so give Xero time to get this right and please don't pressure them into delivering a shallow implementation that exists only to check a checkbox to shut up auditors and winds up disappointing those of us who want to see a robust feature set with JIT provisioning and full role assignments that permits for more granular access support than exists today with the "Invoice Only", "Standard", "Advisor", and "Read Only". In my ideal implementation, there will be permission hooks surrounding all major features and functions, with the ability to provision user accounts in the IdP to give very granular access to every feature that is addressable in all of the menus (Sales, Purchases, Reporting, Accounting, Tax, Contacts), as well as file management, and administration functions. This level of work is non-trivial, and not something that one just "turns on".
As someone who works with authentication technology every day, this is not just a matter of spreading magic pixie dust over the code base for it to work. The first step is that Xero needs to define what they want to achieve with the new feature support (hopefully this has been completed by now). Second, they need to define a permission set that will map to SAML attributes to support the functional definition, and validate that the permission set meets all of the design goals. Third, they need to instrument all of the functions to add the permission set checks that work in parallel with the existing user permissions so that non-SAML sites are not impacted by deploying the new feature. And finally, they need to test the new code extensively to make sure that it is working as designed with no corner cases that would allow for unauthorized access via unprotected paths.
For everyone who is trying to pressure Xero into launching a half-baked SSO implementation "because it limits adoption", take a step back and ask yourself what a botched launch of a major authentication feature would do to Xero's reputation, and how that might "limit adoption" far longer than the "we do not currently support SSO, but that feature is in development" answer currently may.
-
Michael Romano
commented
As a shareholder it’s maddening to see this idea being ignored for so long. All these requests for SSO and MFA could be addressed at once by adopting a professional identity provider and standards. Most Xero customers would already have M365/Entra ID and the fact that this isn’t acknowledged by management is concerning because it’s clearly limiting Xero’s adoption.
-
Lachlan Bunter
commented
Struggling to believe in 2026 an app this big does not have basic SSO functionalities. Completely against Australian Cyber Standards so was immediately Vetoed as an idea. Shame.
-
Peter Bisset
commented
Like everyone else, this is crucial to enable me to ensure application access for core business products is centrally managed.