Signing in with single sign-on
How Recruit decides whether you sign in with your organisation's identity provider, and what to do when single sign-on does not work.
How Recruit decides whether you sign in with your organisation's identity provider, and what to do when single sign-on does not work.
If your organisation uses single sign-on (SSO), you sign in to Recruit with the same account you use for your other work systems, and Recruit does not ask you for a separate password. This article covers what you see on the login page, what happens the first time, and what to do when sign-in fails. The general login screen, two-factor codes and password resets are covered in Logging in to Recruit.
How Recruit decides SSO applies to you
The login page asks for your email address first. When you select Continue, Recruit looks at the part of your address after the @ sign (your email domain) and checks whether your administrator has linked that domain to a single sign-on provider. Capital letters make no difference. What you see next depends on the result:
- The domain is linked to a provider and your organisation requires SSO: you see one button, Continue with followed by your provider's name. There is no password field.
- The domain is linked to a provider but SSO is optional: you see the same button plus a Use password instead link. Select the link to reveal the Password field.
- The domain is not linked to any provider: the Password field appears and you sign in the usual way.
The provider name on the button is whatever your administrator entered as its display name. If you typed the wrong address, select Use a different email to go back to the first step.
If Recruit cannot complete the check, for example because of a connection problem, it shows the password field instead of stopping you. In an organisation that requires SSO, a password entered there is still refused (see the error table below), so reload the page and try again.
Signing in with SSO
- Go to your Recruit login page and enter your work email.
- Select Continue.
- Tick Remember me for 30 days if the device is only used by you. It is unticked by default, and left unticked your sign-in ends when you close the browser.
- Select the Continue with button. Your browser moves to your organisation's sign-in page.
- Sign in there, including any verification step your organisation requires.
- You are returned to Recruit and land on your dashboard. If you arrived by clicking a link in an email, Recruit takes you on to the page that link pointed to.
Recruit asks your provider for a fresh sign-in every time, even if you are already signed in to other work systems in the same browser. This is deliberate, so expect the provider's sign-in page each time you use the button. Finish the sign-in within 10 minutes of selecting the button, and keep cookies enabled in your browser, or the hand-back to Recruit fails.
Google and Microsoft buttons
If your email domain is not linked to a provider, you may see Continue with Google and Continue with Microsoft below the password form, under an or divider. They appear after you have selected Continue, and only when Recruit has them switched on. They follow the same account matching rules as any other single sign-on button, and the Remember me for 30 days box applies to them too.
Your first SSO sign-in and account matching
Single sign-on proves who you are. It does not create a Recruit account and it does not decide what you can see. Your administrator must already have added you as a user in Recruit, and Recruit matches you to that account by email address. Your role, your jobs and your access are exactly what your administrator set up, whichever way you sign in.
This means the email address held by your provider has to be the same address Recruit has for you. If it is not, you get the No account found error described below. Ask your administrator to check which address your Recruit account uses.
A user who has been deactivated in Recruit cannot use it, whichever way they sign in.
What happens to your password
- If SSO is optional, your Recruit password keeps working. Use Use password instead whenever you prefer it.
- If your organisation requires SSO, password sign-in is refused for every address on the linked domain, even with a correct password. Resetting your password does not change this. Your password is not deleted, so if your administrator later turns enforcement off, it works again.
Two-factor authentication with SSO
Recruit's own two-factor prompt (authenticator app code, emailed code or recovery code) belongs to the password route. When you sign in with the SSO button, any verification step comes from your provider, and Recruit does not ask for a code on top.
Enrolment is separate. System Admin, HR and group administrator users must have two-factor authentication set up on their Recruit account, and so must every user if your organisation requires it. If that applies to you and you have not enrolled, Recruit sends you to the two-factor setup page straight after you sign in, including when you signed in with SSO. You cannot skip it. See Setting up two-factor authentication for the steps.
Errors and dead ends
| What you see | What it means and what to do |
|---|---|
| Email is required, or Enter a valid email | The address box is empty or is not a valid address. Correct it and select Continue. |
| Your organisation requires single sign-on, but no provider is configured. Contact your administrator. | Your organisation has made SSO compulsory, but the provider linked to your domain is missing or switched off, so there is nothing to sign in with. Only an administrator can fix this. Passwords stay blocked in the meantime. |
| You must sign in with single sign-on | You entered a password and your organisation requires SSO. Select Use a different email, enter your email again and use the Continue with button. |
| No account found for this email address. Please contact your administrator. | Your provider accepted you, but Recruit has no user with that email address. Ask your administrator to add you, or to correct the address on your Recruit account. Nothing is created for you. |
| Something went wrong. Please try again. | The sign-in could not be completed. Start again from the login page. If it keeps happening, tell your administrator the time it happened. |
| You come back to the login page with no message | The final step of the sign-in failed. Start again from the email step. |
| An error on your provider's own sign-in pages | Those pages belong to your organisation's system, not Recruit. Your IT team or administrator has to resolve it. |
| Session Expired: Your session has expired due to inactivity. Please log in again. | You were signed out. Enter your email and sign in again. |
Who to contact
Most SSO problems need an administrator, because the provider, the linked email domains, the compulsory setting and your user account are all managed by them. Give them the exact message you saw and the email address you tried.