Does Workzoom support single sign-on? Yes. Workzoom supports federated single sign-on (SSO) through SAML 2.0. Your people sign in once with your organization's identity provider, and Workzoom trusts that login. There is no separate Workzoom password to manage, reset, or offboard. Workzoom has a native integration with Microsoft Entra ID (formerly Azure AD); OneLogin, Okta, and any other SAML 2.0 identity provider connect through the standard protocol.
Nortek Solutions Inc., the Toronto-based company behind Workzoom, has built HR and payroll software since 2000. Single sign-on runs on the same multi-tier platform that isolates every client's own database and document repository.
How Workzoom SSO works
Workzoom acts as the SAML 2.0 service provider. Your identity provider (IdP) holds the credentials and authenticates the user. It sends Workzoom a signed assertion confirming who they are, and Workzoom grants access. Both sign-in directions work: users can launch Workzoom from your company portal, or land on Workzoom first and get redirected to your IdP to sign in. This runs on the same Workzoom platform architecture that isolates every client's data.
Authentication happens at your identity provider, so your existing security policies carry straight through to Workzoom. Conditional access, device trust, IP restrictions, and session lifetime all stay governed by the IdP you already run.
Supported identity providers
Workzoom has a native integration with Microsoft Entra ID, and supports Okta and OneLogin through the standard SAML 2.0 protocol:
- Microsoft Entra ID (formerly Azure Active Directory)
- OneLogin
- Okta
Any other identity provider that speaks SAML 2.0 connects the same way. This includes Google Workspace, Ping Identity, and on-premise federation services. If your provider supports SAML 2.0, it works with Workzoom.
Configuring SAML 2.0 single sign-on
Setup is a short, guided exchange between your IdP administrator and the Workzoom team. Workzoom stays the source of truth for roles and permissions. The identity provider only handles the login.
- Workzoom provides your service provider (SP) metadata. This includes the Assertion Consumer Service (ACS) URL and the Entity ID for your environment.
- Your administrator registers Workzoom as an application in your identity provider using that metadata. They map the user identifier, typically email or UPN, to the matching Workzoom record.
- You share your IdP metadata and signing certificate with the Workzoom team. This means the X.509 public certificate and the SSO endpoint.
- Workzoom enables federated login on your account. Workzoom then runs a test sign-in with you before it goes live for all users.
There is no charge to enable SSO, and no separate identity-management add-on to license. See full Workzoom pricing. If your team needs help during setup, contact Workzoom support.
Access control after sign-in
Single sign-on governs who can get in. Role-based access control governs what they see once they are in. Workzoom grants each user only the data and functions their role permits. Every client's data sits in an isolated database.
For the full picture of how Workzoom protects your data, including encryption, hosting, and certifications, see the Workzoom technology platform. Identity data shared during SSO setup falls under the Workzoom Data Processing Agreement.
Trusted by teams already running Workzoom
Workzoom's SAML 2.0 single sign-on runs on the same platform HR and payroll teams already trust. See who's behind Workzoom or read customer case studies.