Organisational sign-in (Active Directory, Azure AD and LDAP)
Staff sign in to Porsino with their network or organisational account — a step-by-step guide for the IT team.
Go to team settings🏢 What is organisational sign-in?
With organisational sign-in, staff sign in to Porsino with their network account (Active Directory) or organisational account (Azure AD / Entra ID, Keycloak, Google Workspace or any standard OpenID Connect provider) and automatically join the organisation's team with the right role.
Where: Panel › Settings › Teams › the «Organisational sign-in» button on the team card. Only the team owner can change the settings; team admins can view them and run «Test connection».
① Verify the organisation's email domain (required)
- 1 In «Organisation email domains», enter the domain (e.g. company.ir) and click «Add domain».
- 2 Create a TXT record in the domain's DNS. Its value is the porsino-verification=… string Porsino shows; there is a copy button next to it.
- 3 A few minutes later, click «Verify».
Type: TXT Name: _porsino.company.ir (or company.ir) Value: porsino-verification=…
② Option A: Active Directory / LDAP
Set the method to «LDAP / AD». The Porsino server connects to the directory with a service account, finds the user and checks their password with a bind.
- 1 Host: the domain controller or the LDAP service name.
- 2 Port and encryption: LDAPS on 636; usually 389 for StartTLS. «No TLS» sends passwords in clear text; use it only on a secure internal network.
- 3 Organisation CA certificate: if the domain controller's certificate was issued by your internal CA.
- 4 Service account Bind DN and password: a read-only account. The password is stored encrypted and never shown again.
- 5 Enter the search Base DN and the user filter. {username} is what the user types; it is safely escaped.
Host: dc1.corp.local
Port: 636 (LDAPS)
Bind DN: CN=porsino-svc,OU=Service,DC=corp,DC=local
Base DN: DC=corp,DC=local
Filter: (&(objectClass=user)(sAMAccountName={username}))② Option B: OpenID Connect — Azure AD / Microsoft Entra ID
Set the method to «OpenID Connect» and copy the Redirect URI that Porsino shows.
- 1 In Entra admin center › App registrations › New registration, create an application. «Accounts in this organizational directory only», with a Web-type Redirect URI.
- 2 In Certificates & secrets, create a new client secret and put its Value in Porsino's «Client Secret».
- 3 Enter the Issuer and Client ID in Porsino; scopes: openid email profile. The Issuer must include your tenant ID, not common.
- 4 For roles: Token configuration › Add groups claim (Security groups). In role mapping, enter each group's Object ID; if you use App roles, set the claim to roles.
Redirect URI: https://porsino.com/api/v1/auth/sso/callback Issuer: https://login.microsoftonline.com/<tenant-id>/v2.0 Client ID: <Application (client) ID> Scopes: openid email profile
🔑 Keycloak and Google Workspace
- 1 Keycloak: in Realm › Clients, create an OpenID Connect client. Client authentication on, Standard flow on, and Valid redirect URIs set to the address above.
- 2 Copy the client secret from Credentials into Porsino.
- 3 For groups, add a Group Membership mapper with the claim name groups. Values look like /hr-admins; enter the same values in role mapping.
- 4 Google Workspace: create a Web-type OAuth client in Google Cloud Console and register the Redirect URI. Google does not send groups in the token, so everyone joins with the «default role».
Keycloak: https://<keycloak-host>/realms/<realm> Google: https://accounts.google.com
③ Roles, switching on and «organisational sign-in only»
- 1 Map groups to roles; for example HR managers → «Admin», specialists → «Designer». The highest matching role applies and is re-synced with the organisation on every sign-in.
- 2 Choose a «default role» for people who are in no mapped group. With «Mapped group members only», they cannot sign in at all.
- 3 Enter an organisation ID, for example acme. Staff type it on the sign-in page instead of an email, or open the direct link.
- 4 Turn on «Organisational sign-in enabled» and save.
https://porsino.com/login?sso=acme
Want to set this up on your own form? Creating an account and using Porsino is Free .
Start for freeRelated guides
- Custom domain: your forms on your own addressOpen your forms and exams on a Porsino subdomain or your own domain (such as forms.company.ir).
- API, webhooks and Google SheetsConnect responses to your other systems.
- API for developers: keys, scopes and examplesCreate a key and read or write forms, responses and reports from your own software.
- AdminSuperadmin panel: users, service health and global settings.
- Appearance and brand kitMatch the form's layout, theme, colors, logo and font to your organization's identity.