Traceforce for MSPs
Setting up single sign-on for Traceforce
Traceforce signs in through your company's existing single sign-on. You'll create a SAML application in your identity provider, then send us the metadata URL it generates. That URL is the only thing we need to finish setting up your account.
Before you start
You'll need to be signed in to the Microsoft Entra admin center as an Application Administrator or Cloud Application Administrator.
Create the application
- Go to the Microsoft Entra admin center at entra.microsoft.com, then open Identity › Applications › Enterprise applications.
- Click New application, then Create your own application.
- Name it Traceforce, select Integrate any other application you don't find in the gallery (Non-gallery), and click Create.
Configure SAML
In your new application, open Single sign-on and choose SAML. Under Basic SAML Configuration, click Edit and enter the five values below, then click Save.
Check your Name ID before moving on
Under Attributes & Claims, the Unique User Identifier (Name ID) has to be the user's email address. Entra's default is user.userprincipalname, which works when your UPNs match your email addresses.
If your sign-in domain is different from your email domain, which is common when a company changed domains after setting up Microsoft 365, change it to user.mail instead.
Assign your users
Go to Users and groups, click Add user/group, and assign everyone who should have access to Traceforce.
Don't skip this step
Entra blocks unassigned users by default. If nobody is assigned, sign-in will fail even after your tenant is fully set up on our end.
Copy your metadata URL
Back on the Single sign-on page, scroll to the SAML Certificates section and copy the App Federation Metadata Url.
It looks like this:
https://login.microsoftonline.com/<tenant-id>/federationmetadata/2007-06/federationmetadata.xml?appid=<app-id>
That's the URL we need from you.
Send it to us
Setting up a client, not your own tenant?
Steps 1 through 4 are the same, but don't use this form. When you add a client organization in Traceforce, you paste their metadata URL into the Metadata URL field on the Org Access page yourself.
The form below is only for setting up your own tenant with us. Onboard a client and deploy Traceforce covers the client steps.
Paste your metadata URL into our short form along with your sign-in domain. Once we have it, we'll finish setting up your account and email you your login and everything you need to run your first AI Risk Assessment.
Submit your SAML detailsUsing Okta, OneLogin, or another provider?
Create a custom SAML 2.0 app in your provider using the same values from Step 2. Every provider uses the same values, only the field names change. In OneLogin, also set the SAML flow to SP-initiated.
| Traceforce value | Okta | Microsoft Entra | OneLogin |
|---|---|---|---|
| ACS URL (/saml/acs) |
Single Sign On URL, Recipient URL, Destination URL | Reply URL (ACS URL) | ACS (Consumer) URL, Recipient, ACS URL Validator |
| Entity ID (/saml/metadata) |
Audience Restriction | Identifier (Entity ID) | Audience (EntityID) |
| SLO URL (/saml/slo) |
Single Logout URL (under Show Advanced Settings) | Logout Url | Single Logout URL |
| Sign-on URL (/login) |
Not used | Sign on URL | Login URL |
| Relay State (/auth/callback) |
Default Relay State | Relay State | Relay State |
| Name ID (Email address) |
Name ID Format | Unique User Identifier | SAML nameID format |
Once the app is created, note the SAML 2.0 metadata URL your provider generates, then submit it through the same form above. If you're setting up a client organization rather than your own tenant, paste that URL into Traceforce instead of submitting the form.
Next: onboard your first client
Once your tenant is live, you'll add each client as an organization in Traceforce and deploy the agent and browser extension through your RMM on Windows, or your MDM on macOS. Removing it later is on the same page.
Want to do this together on a call? Book a technical walkthrough and we'll set it up with you.