Login - Enable Microsoft Entra ID Single Sign On
Ability to use Azure Active Directory for MFA.
Purpose: It makes Microsoft users easily log into Xero.
Hi everyone, we appreciate all the feedback and votes on this idea. We know using Microsoft Entra ID SSO is now common practice for some businesses and being able to access Xero via a native integration with Entra ID would streamline how your teams log in and get set up in Xero, as well as help in managing access for larger teams and keeping things secure.
Our product team have been working with a small limited group of Partners to develop SSO capabilities. Though we can't give any definite timelines yet, we’ll keep this thread updated with news. Thanks
-
Alex Steer
commented
Thank you Kelly,
Very grateful that you picked this critical SaaS security feature request up and are finally taking it seriously.
Note that there's a lot of ideas asking for the same kind of generic SAML2.0 / SCIM / OIDC type functionality going back over 10 years. Over that time, as you'll have seen from our comments a lot of faith in Xero and this process has been lost.
I can see you aren't giving a definite timeline or commitment but even if you can't do that, what would be great is either when you will be able to offer us that timeline, or when we can at least expect another update so we know this isn't just words.
Many thanks again for finally getting your team onboard.
-
Ashley Brown
commented
Works for me incognito:
https://feedback.xero.com/jfe/form/SV_29u5ddCM77x11aK -
Mark Anyon
commented
That feedback link below doesnt work. I note that https://feedback.xero.com/ goes to Xeros internal Okta SSO login prompt....!
-
Ashley Brown
commented
Smash them on the survey guys
https://feedback.xero.com/jfe/form/SV_29u5ddCM77x11aK? -
Erin Marney
commented
We are going through the process of moving everything possible to SSO and feel at this time in late 2025 Xero is going to fall behind if they don't act on these capabilities to offer their customers. Move it up the development list.
-
Chris Neophytou
commented
@Andrew A - fair comment. Xero SSO would be better and cheaper and if it arrives we will definitely use it!
-
Ray Brindley
commented
Still can't believe how utterly pathetic Xero is for this. Every other major vendor can do this why is Xero so utterly inept and insists on insecure methods of authentication.
Xero is the biggest vulnerability in our organisation because it's the only system that doesn't have SSO. -
Andrew Anderson
commented
@Chris Okta's SWA is a browser plugin solution that performs credential stuffing into login forms.
While it would permit for using Okta as a launching point, it does not provide the same level of capabilities and (I would argue) security that a native OIDC/SAML solution would provide.
-
Nigel Newsom
commented
Having support for OIDC and SAML 2 is very important, to enable conditional access. Having onboard and off-boarding would be great as well
-
Chris Neophytou
commented
Eureka?
Potential game-changer moment for Xero user cyber security.
Okta (starter licence) SWA provides SSO functionality for apps that don't.
Still trialing it but I hope it's the solution we've all been trying to find for such a long long time.
Good luck community.
-
David Long
commented
Still waiting for Xero to take security seriously in 2025.
-
Philip Owens
commented
As an Identity Security consulting services company, and a 10+ year user of Xero accounting software across multiple countries, we have been eagerly awaiting an announcement from Xero to address this most basic requirement, that seemingly most other SaaS vendors already offer. We have tried to build our own, but due to limitations in the product, were unable to achieve a viable SSO solution. However, what we were able to build is an automated provisioning/de-provisioning tool from Xero Payroll to on-prem AD or Entra ID. If anyone is interested in this capability, here is a link to more information. https://assertiv.com/hr2entra/
-
Thomas Samuel
commented
Hi Xero, is it possible to get an update to this from your development/engineering team?
-
Alistair Weddell
commented
Cant wait to find something that has Xero's features so I can migrate off this shocking insecure platform. What a joke in 2025 with all the breaches, that something that costs so little to build would be dragged along for so long...
Pathetic.
-
Justin Fletcher
commented
It is unbelievable that this remains unavailable and @xero has not provided an update in over a year. It would simplify user administration and stop exposing businesses to weaknesses that can be addressed.
-
Nisheet Patel
commented
Surely this has to be a standard offering in cloud platforms considering the security improvements it would bring. What's there still to think about?
-
Kai Howells
commented
This request has been hanging in for so long that it talks about Azure Active Directory instead of Entra ID.
Come on Xero, it's time to get serious about security and enterprise integration.
-
Stuart Ellidge
commented
@Xero how many votes and comments does a ticket need to get picked up?! It's becoming insulting now.
-
Craig Reynolds
commented
I'm amazed that something I take for granted on pretty much every SaaS platform is missing from Xero with no commitment to actually do anything. When we evaluate new platforms SSO is one of the key criteria we measure against.
A timeline or roadmap is needed Xero.
-
Mark Anyon
commented
Here is the linkedin for Security (CISO) at Xero, I wonder how high this topic sits on her priority list....