SSO - Add SAML authentication support
Implementing SAML for authentication to allow businesses to manage the identities themselves such as businesses that connect their identity provider to LDAP
Purpose: Allow staff to login easier and depending on the identity provider setup securely.
Hi everyone, we appreciate adding SAML authentication support to Xero is important to you all. But to be open, this is not on our team’s roadmap right now and we'll close the idea here to give clarity to anyone coming across.
As I see that some of you have mentioned Azure SSO, we have an idea for this that you can join in. Alternatively, if there's a different SSO provider that you'd like to integrate with, start a new idea.
-
Paul Harvey commented
Yes please prioritise this, this is an important step for many organisations security.
-
Steve Bates commented
I really expected to find that this was a 15 minute job to enable SSO.
Auth0 standards are mature this should have been done several years ago.
-
Tyson O'Connell commented
Team Xero,
It is imperative that Xero implements Security Assertion Markup Language (SAML) Single Sign-on (SSO) capability.
In 2024, it is a considerable security issue not having this, posing risk to Xero customers.
Happy Xero customers should not be forced to consider alternative competitor platforms as a result of this vulnerability.
Please recognise that many organisations require Identity and Access Management (IAM) solutions, such as Okta and other SSO providers.
Please address this concern for us ASAP and confirm a date for when this capability will be available.
Thank you. -
Adam Jones commented
It's causing my organisation big problems that you don't support this. It's one of the main reasons the IT department is pushing us to change to other software.
-
Jan van der Kolk commented
Critical to implement. No need to support specific providers, as long as you support the SAML standard.
-
Aaron Angel commented
I think the mutliple SSO ideas should be combined, as they are essentially the same idea. Spreading out the votes only delivers poor visibility into user demands to product managers.
Today, SSO products that small to medium businesses are using, including Google Workspace, Microsoft Entra (formerly Azure AD), Salesforce, and more, all support self-configurable SAML SSO out of the box. Adding this would go a long way toward improving adoption and integration of your product. In 2023, people have grown tired of too many passwords and the disparity of security requirements between vendors.
SSO is no longer an esoteric enterprise requirement. It's a minimum requirement for modern SaaS products.
We are considering more expensive products and considering budgets and the potential for migrations because of basic requirements like this.
-
Peter Laycock commented
Security Engineer here.
For a financial product not to have this given the sensitivity of the data it holds it is rather shocking.
I would suggest you sort this rather simple thing out. Time has marched on, the 90's are gone. Modern security practices are needed.
-
Richard Crozier commented
Critical in 2023. Please implement.
-
Geoff Boyce commented
SAML is an open standard and will make Xero compatible with all enterprise identity providers, not just Azure AD. Surely you guys know this given the length of time it has been a feature request?
-
Steve Orfanos commented
This is a big fail for third party vendor assessment.
-
Richard Crozier commented
It should be on your roadmap, SSO is now common and critical for business security. Very difficult to understand the reason it can't be implemented.
-
Andrew Quill commented
This along with "MFA - Enable Windows Azure Active Directory Single Sign On" is beyond believe that this isn't base build. See my comments on the other feature request but serious Xero Developers, this MUST be enabled or the worlds demand for security will see your market share shrink quickly!
-
Adam Bulgatz commented
This remains critical, even though the vote count was reset with this new ideas website. Used to have hundreds of votes at least...
-
Donald Damjanovic commented
This feature is overdue.. Xero/WorkflowMax SAML 2.0 integration with Microsoft Azure AD is a critical (and a now very common) security control feature. Please help your customers protect their Xero/WorkflowMax access and enable a secure and seamless login experience with SAML authentication support.
-
Matthew Nunns commented
Need Azure AD SSO support, it's a must have
-
Geoff Boyce commented
How is this not a feature yet? This was one of the most highly voted and longest running feature requests. Years have passed by with promises that this feature was on the roadmap and still nothing.
I find it astounding that with the launch of “product ideas”, all previous feature requests and voting had been wiped clean. Prior to that was the removal of dates for people’s comments to hide just how long people had been asking for these features. There really isn’t any point having a user feedback community if you simply don’t want to listen.
-
Adrian Bole commented
Or business is all about identity and security and sso is one of the things we recommend to our customers. It’s good for us if we can practice what we preach and can boat our own security with MFA when Xero doesn’t always provide it.
-
Ashley Knowles commented
why isn't this implemented yet?
-
Marina Levi commented
supporting SSO and user provisioning and allow gallery predefined AzreAD integration will allow customers to perform IdP management by themselves and reduce pressure from Xero team. So it's not benefit customers only but helps to save time for Xero-own eng team.
Also, supporting SAML - means supporting modern standards (reputational/brand-related) for Xero.
Please implement saml based sso and user provisioning! -
Nathan Morris commented
How is SAML authentication support not a thing yet?