Single sign-on (SSO) lets your employees log in to Ben with their normal company login instead of a separate Ben password — one less password to lose or reset, and it keeps sign-in within your organisation's own security controls.
This guide covers turning on SSO for Ben using Microsoft or Google with OIDC — the option Ben has preconfigured for these two providers.
A note for admins
As the admin for your Ben portal, you may not be the person who sets up SSO — this is usually handled by your organisation's IT or Security team. We recommend you send this article to them so they have what they need.
Once they've turned it on, you can let your employees know they can log in to Ben with SSO.
If you're weighing up OIDC against SAML, see SAML vs OIDC — but which one is right for your organisation is a decision for your IT or Security team.
Why OIDC for Microsoft and Google
Ben comes with Microsoft and Google OIDC preconfigured. That means there's no metadata to exchange and no connection to build from scratch — unlike SAML, which Ben sets up per customer. If your identity provider is Microsoft or Google, OIDC is the quickest, simplest way to connect.
How to turn it on
Because OIDC is preconfigured, enabling it is a change Ben makes for your instance, followed by a step on your side:
Contact your technical account manager or our support team and ask to enable Microsoft or Google OIDC for your company.
Ben switches your company's login to the Microsoft or Google OIDC option.
You (or your IT or Security team) complete the connection on your Microsoft (Entra) or Google side, so your organisation allows Ben as an application. Your technical account manager will walk you through the exact steps for your identity provider.
Once it's live, your people sign in to Ben through your normal Microsoft or Google login.
If you also use SAML with Microsoft
If your company has SAML set up with Microsoft as well, users who sign in via Microsoft can end up creating a second, separate Ben application in your Microsoft tenant that uses OIDC rather than SAML. If you want to avoid that, see the steps in Setting up Microsoft SSO for your employees (SAML).
Need help?
If you get stuck turning OIDC on, contact your technical account manager or our support team. However, whether OIDC or SAML is right for your organisation is a decision for your IT or Security team.
