Traceforce for MSPs

Setting up single sign-on for Traceforce

Traceforce signs in through your company's existing single sign-on. You'll create a SAML application in your identity provider, then send us the metadata URL it generates. That URL is the only thing we need to finish setting up your account.

About 10 minutes Microsoft Entra walkthrough Okta and OneLogin values included

Before you start

You'll need to be signed in to the Microsoft Entra admin center as an Application Administrator or Cloud Application Administrator.

01

Create the application

  1. Go to the Microsoft Entra admin center at entra.microsoft.com, then open Identity › Applications › Enterprise applications.
  2. Click New application, then Create your own application.
  3. Name it Traceforce, select Integrate any other application you don't find in the gallery (Non-gallery), and click Create.
02

Configure SAML

In your new application, open Single sign-on and choose SAML. Under Basic SAML Configuration, click Edit and enter the five values below, then click Save.

Traceforce configuration values
Identifier (Entity ID)
https://app.traceforce-auth.com/auth/v1/sso/saml/metadata
Reply URL (Assertion Consumer Service URL)
https://app.traceforce-auth.com/auth/v1/sso/saml/acs
Sign on URL
https://www.traceforce.co/login
Relay State
https://www.traceforce.co/auth/callback
Logout Url
https://app.traceforce-auth.com/auth/v1/sso/saml/slo

Check your Name ID before moving on

Under Attributes & Claims, the Unique User Identifier (Name ID) has to be the user's email address. Entra's default is user.userprincipalname, which works when your UPNs match your email addresses.

If your sign-in domain is different from your email domain, which is common when a company changed domains after setting up Microsoft 365, change it to user.mail instead.

03

Assign your users

Go to Users and groups, click Add user/group, and assign everyone who should have access to Traceforce.

Don't skip this step

Entra blocks unassigned users by default. If nobody is assigned, sign-in will fail even after your tenant is fully set up on our end.

04

Copy your metadata URL

Back on the Single sign-on page, scroll to the SAML Certificates section and copy the App Federation Metadata Url.

It looks like this:

https://login.microsoftonline.com/<tenant-id>/federationmetadata/2007-06/federationmetadata.xml?appid=<app-id>

That's the URL we need from you.

05

Send it to us

Setting up a client, not your own tenant?

Steps 1 through 4 are the same, but don't use this form. When you add a client organization in Traceforce, you paste their metadata URL into the Metadata URL field on the Org Access page yourself.

The form below is only for setting up your own tenant with us. Onboard a client and deploy Traceforce covers the client steps.

Paste your metadata URL into our short form along with your sign-in domain. Once we have it, we'll finish setting up your account and email you your login and everything you need to run your first AI Risk Assessment.

Submit your SAML details
Using Okta, OneLogin, or another provider?

Create a custom SAML 2.0 app in your provider using the same values from Step 2. Every provider uses the same values, only the field names change. In OneLogin, also set the SAML flow to SP-initiated.

Traceforce value Okta Microsoft Entra OneLogin
ACS URL
(/saml/acs)
Single Sign On URL, Recipient URL, Destination URL Reply URL (ACS URL) ACS (Consumer) URL, Recipient, ACS URL Validator
Entity ID
(/saml/metadata)
Audience Restriction Identifier (Entity ID) Audience (EntityID)
SLO URL
(/saml/slo)
Single Logout URL (under Show Advanced Settings) Logout Url Single Logout URL
Sign-on URL
(/login)
Not used Sign on URL Login URL
Relay State
(/auth/callback)
Default Relay State Relay State Relay State
Name ID
(Email address)
Name ID Format Unique User Identifier SAML nameID format

Once the app is created, note the SAML 2.0 metadata URL your provider generates, then submit it through the same form above. If you're setting up a client organization rather than your own tenant, paste that URL into Traceforce instead of submitting the form.

Next: onboard your first client

Once your tenant is live, you'll add each client as an organization in Traceforce and deploy the agent and browser extension through your RMM on Windows, or your MDM on macOS. Removing it later is on the same page.

Onboard a client and deploy Traceforce

Want to do this together on a call? Book a technical walkthrough and we'll set it up with you.