Organisational sign-in (Active Directory, Azure AD and LDAP)

Staff sign in to Porsino with their network or organisational account — a step-by-step guide for the IT team.

Go to team settings

🏢 What is organisational sign-in?

With organisational sign-in, staff sign in to Porsino with their network account (Active Directory) or organisational account (Azure AD / Entra ID, Keycloak, Google Workspace or any standard OpenID Connect provider) and automatically join the organisation's team with the right role.

Where: Panel › Settings › Teams › the «Organisational sign-in» button on the team card. Only the team owner can change the settings; team admins can view them and run «Test connection».

Staff passwords are never stored in Porsino.
Creating and turning on the connection requires the "Enterprise" plan; after that, staff sign-in is never locked.

① Verify the organisation's email domain (required)

  1. 1 In «Organisation email domains», enter the domain (e.g. company.ir) and click «Add domain».
  2. 2 Create a TXT record in the domain's DNS. Its value is the porsino-verification=… string Porsino shows; there is a copy button next to it.
  3. 3 A few minutes later, click «Verify».
Sample DNS record
Type:  TXT
Name:  _porsino.company.ir   (or company.ir)
Value: porsino-verification=…
On an on-premises Porsino installation without public DNS, the system administrator can approve the domain with «Manual verification».
Until the domain is verified, no one can use organisational sign-in — this stops others from misusing the organisation's name.
Public email domains (gmail.com and the like) are not accepted.

② Option A: Active Directory / LDAP

Set the method to «LDAP / AD». The Porsino server connects to the directory with a service account, finds the user and checks their password with a bind.

  1. 1 Host: the domain controller or the LDAP service name.
  2. 2 Port and encryption: LDAPS on 636; usually 389 for StartTLS. «No TLS» sends passwords in clear text; use it only on a secure internal network.
  3. 3 Organisation CA certificate: if the domain controller's certificate was issued by your internal CA.
  4. 4 Service account Bind DN and password: a read-only account. The password is stored encrypted and never shown again.
  5. 5 Enter the search Base DN and the user filter. {username} is what the user types; it is safely escaped.
Sample Active Directory values
Host: dc1.corp.local
Port: 636 (LDAPS)
Bind DN: CN=porsino-svc,OU=Service,DC=corp,DC=local
Base DN: DC=corp,DC=local
Filter: (&(objectClass=user)(sAMAccountName={username}))
Attribute mapping (AD defaults): email mail, name displayName, personnel code employeeID, department department, stable ID objectGUID and groups memberOf. For OpenLDAP, click «OpenLDAP defaults».
Users can type ali or CORP\ali. To also allow ali@company.ir, add userPrincipalName to the filter.
An account disabled in AD is removed from the team on its next sign-in attempt.
The Porsino server must reach the LDAPS port. On the public porsino.com service, internal network addresses (10.x, 192.168.x, …) are not accepted; either expose LDAPS on a public address (only for the Porsino server's IP) or use OpenID Connect.

② Option B: OpenID Connect — Azure AD / Microsoft Entra ID

Set the method to «OpenID Connect» and copy the Redirect URI that Porsino shows.

  1. 1 In Entra admin center › App registrations › New registration, create an application. «Accounts in this organizational directory only», with a Web-type Redirect URI.
  2. 2 In Certificates & secrets, create a new client secret and put its Value in Porsino's «Client Secret».
  3. 3 Enter the Issuer and Client ID in Porsino; scopes: openid email profile. The Issuer must include your tenant ID, not common.
  4. 4 For roles: Token configuration › Add groups claim (Security groups). In role mapping, enter each group's Object ID; if you use App roles, set the claim to roles.
Azure AD values
Redirect URI: https://porsino.com/api/v1/auth/sso/callback
Issuer: https://login.microsoftonline.com/<tenant-id>/v2.0
Client ID: <Application (client) ID>
Scopes: openid email profile
If users have no email claim, set «Email claim» to preferred_username.

🔑 Keycloak and Google Workspace

  1. 1 Keycloak: in Realm › Clients, create an OpenID Connect client. Client authentication on, Standard flow on, and Valid redirect URIs set to the address above.
  2. 2 Copy the client secret from Credentials into Porsino.
  3. 3 For groups, add a Group Membership mapper with the claim name groups. Values look like /hr-admins; enter the same values in role mapping.
  4. 4 Google Workspace: create a Web-type OAuth client in Google Cloud Console and register the Redirect URI. Google does not send groups in the token, so everyone joins with the «default role».
Issuer
Keycloak: https://<keycloak-host>/realms/<realm>
Google: https://accounts.google.com
«Test connection» reads the discovery document and signing keys and tells you if anything is missing.

③ Roles, switching on and «organisational sign-in only»

  1. 1 Map groups to roles; for example HR managers → «Admin», specialists → «Designer». The highest matching role applies and is re-synced with the organisation on every sign-in.
  2. 2 Choose a «default role» for people who are in no mapped group. With «Mapped group members only», they cannot sign in at all.
  3. 3 Enter an organisation ID, for example acme. Staff type it on the sign-in page instead of an email, or open the direct link.
  4. 4 Turn on «Organisational sign-in enabled» and save.
Direct sign-in link for staff
https://porsino.com/login?sso=acme
Staff without an account get one on first sign-in; anyone who already registered with the same email is linked to that account.
All changes, sign-ins and failed sign-ins are recorded in «Events», and «Organisation users» lists everyone who has signed in (with personnel code and department).
Turn on «Organisational sign-in only» once you are sure sign-in works; from then on password and Google sign-in are closed for verified-domain emails. The team owner (for emergency access) and the system administrator can always still sign in with a password.

Want to set this up on your own form? Creating an account and using Porsino is Free .

Start for free