Hi. How can we help?

Enterprise SSO for Back Office

Single Sign-On (SSO) allows your employees to log in to the Back Office using your company's existing corporate login. Enterprise SSO provides secure access while also simplifying user credentials.

Back Office users must still be created before they can sign in via SSO.

Enabling this feature will only apply SSO to logging into the Back Office. SSO cannot be enabled for POS login.

Lightspeed Restaurant supports any identity provider (IdP) compliant with the OIDC (OpenID Connect) protocol, including:

• Microsoft Entra ID (Azure AD)
• Okta
• Google Workspace

Setting up SSO

To set up SSO for your organization, contact your Account Manager to begin the process.

You'll be asked to provide the following information for both your test and live environment. SSO is initially configured in your Lightspeed Restaurant test environment to validate the process and details. Once validated, SSO login requirements will apply to users on your live Lightspeed Restaurant account.

Field Description Example value
Business name Your company/business name Lightspeed Café
Environment Test or Production Test
Client ID From your IdP's OIDC app registration 0oa2hl2inow5Uqc6c000
Client Secret The secret associated with your OIDC app registration ab_live_9b24f4l6z91835tpq7Sx92
Issuer URL Your IdP's OIDC issuer URL https://login.microsoftonline.com/{tenant}/v2.0
Email Domains The domain(s) that should use SSO yourcompany.com

Logging in with SSO

Enabling SSO for Back Office does not automatically create Back Office users in Lightspeed Restaurant. 

Before an employee can use SSO credentials, an admin must first create the user in the Back Office and assign them groups, permissions, location assignments, and more. Ensure that their email address matches the one used for their SSO login credentials. 

  1. Open the Back Office login page.
  2. Click Log in with Enterprise SSO.
    SSO Back Office login button
  3. Enter your company email address (for example, xyz@yourcompany.com).
    SSO Back Office login page
  4. You'll be redirected to your company's login portal (Okta, Entra ID, etc.).
  5. Authenticate your login, including any multi-factor authentication your company requires.

Completing this process returns the user to the Back Office, logged into their account.

Managing Back Office users with SSO

Even with SSO enabled, managing users through the Back Office remains an important aspect of controlling what your users have access to. Keep in mind the following details about SSO:

  • Email domain is enforced: Any user with an email login address that has an SSO-enabled email domain (for example, xyz@yourcompany.com) must use SSO. A username and password login will no longer work for them.
  • Outside parties do not use SSO: Users with a different email domain (for example, xyz@agency.com) must be created and use username and password credentials as normal.
  • Password reset emails are disabled: For security, password recovery must pass through SSO methods and not the Back Office.
  • SSO is reversible: You can request Lightspeed Support to disable SSO for users and return to username and password logins.
  • Roles & permissions: Roles and permissions for your users are managed in the Back Office using user groups, not using your identity provider.
  • Offboarding: To fully remove a user from the Back Office, you need to deactivate the user in the Back Office. This does not automatically happen via SSO.

FAQ

  • Reach out to Lightspeed support if your IdP is unavailable. We can help you unblock or temporarily disable SSO.
  • Yes, provide all email address domains that should use SSO during the setup process.
  • Users from non-SSO domains can use their username and password credentials. SSO enforcement is done by email domain, not per business or location.
  • With SSO enabled, there is no requirement to send passwords to new employees. Users can click on SSO login to log into the Back Office. However, if SSO becomes disabled due to an IdP outage, they will need their username and password to log in.
  • If SSO is disabled, users can login with their username and password credentials. If they forget their password, they can follow the Reset password procedure.

Was this article helpful?

0 out of 0 found this helpful