Single Sign-On (SSO)

Single Sign-On (SSO) for Cloud PBX

Sign in to your phone system with the company account your team already uses

🔒 Single Sign-On (SSO) is a login method that lets people reach several work tools with one company account. In a Cloud PBX, it means the phone system no longer keeps its own passwords. It asks your identity provider, such as Microsoft Entra ID, Google Workspace or Okta, to confirm who the user is.

How SSO Works

💡 In short: the phone system stops storing passwords of its own. It asks your company directory whether this person is allowed in, and applies the answer.

1️⃣ Someone opens the phone system

A user launches the Cloud PBX portal, the softphone or the mobile app.

2️⃣ The PBX hands the login over

Instead of showing a password box, the phone system redirects the user to your identity provider.

3️⃣ Your provider checks identity

The directory verifies the account and applies its own rules: multi-factor checks, managed devices, allowed locations.

4️⃣ The user returns signed in

The provider sends back a signed confirmation. The PBX opens with the right role, extension and permissions.
🔓 What SSO unlocks: one company login for the phone system, multi-factor and conditional access applied automatically, instant removal of access when someone leaves, a single sign-in audit trail, and optional automatic user provisioning.

Types of SSO You Already Use

You have probably used SSO without noticing. These are the four types you are most likely to meet around a Cloud PBX.
Enterprise SSO (SAML-based)
Uses SAML or OAuth with an identity provider like Microsoft Entra ID, Google Workspace, or Okta.
Federated SSO: Connects multiple organizations. For example, if your company works closely with a partner firm, federated SSO lets employees from both organizations access shared tools using their own company credentials: useful for cross-border collaboration in the LU/DE/FR/BE region.
Desktop SSO (Kerberos): Common in Windows environments. When you log into your Windows computer at work, you're already authenticated for other Microsoft services: no need to type your password again. Some Cloud PBX systems integrate with this for seamless desktop access.

Why It Matters for Your Business

🙌 Less friction for people

✅ One familiar company login, no extra password
✅ Nothing new to reset or forget
✅ New joiners can call on day one

🛠️ Less work for IT

✅ Access granted and removed in one place
✅ Leavers lose phone access the moment they are offboarded
✅ Optional automatic provisioning through SCIM

🛡️ Stronger central security

✅ MFA, password rules and device checks apply everywhere
✅ One audit trail of who signed in, when and from where
✅ Helps evidence access control under GDPR
📋 At a glance
  • Protocols: SAML 2.0, OAuth 2.0 and OpenID Connect
  • Best fit: teams already on Microsoft 365, Google Workspace or Okta
  • Typical setup time: 30 to 120 minutes
  • Common extra: automatic user provisioning through SCIM
  • Usually found on: higher plan tiers, or as a paid add-on

What to Look For

🔐 Your own provider is supported

Ask for the exact list: Microsoft Entra ID (formerly Azure AD), Google Workspace, Okta, OneLogin, JumpCloud. A provider saying it supports SSO is not enough, it must support yours.

📜 SAML 2.0 or OpenID Connect

These two open standards are what modern identity systems speak. Support for at least one means the connection can be set up with configuration values rather than custom development.

👥 Automatic user provisioning

The strongest setups create, update and remove phone accounts from your directory automatically, usually through SCIM. Offboarding then becomes a single action instead of two.

🆘 A documented emergency access path

If your identity provider is unreachable, you still need a way in. Ask for the break-glass administrator procedure in writing before you sign, not during an outage.
🔧 Setting it up: you need administrator rights on both sides. The provider gives you three configuration values, an entity ID, a sign-on URL and a certificate, which you paste into your identity system. See deployment and administration for the wider rollout picture.

Is SSO Worth It for Your Team?

✅ Set it up if

  • You already run Microsoft 365, Google Workspace or Okta
  • Around 10 or more people use the phone system
  • Staff join or leave regularly
  • You need to show auditors who had access
  • You already require MFA on your other tools

🟡 It can wait if

  • You have no central identity provider yet
  • Fewer than 10 people use the phone system
  • It sits behind a plan tier you do not otherwise need
  • Your team is small and stable
  • Desk phones, not apps, are how people mainly call
🇱🇺 How to verify support: availability differs a lot between providers, and marketing pages are often vague. Check the provider's own documentation and ask for the protocol name in writing. Mixvoip publishes its business offer at https://www.mixvoip.com and its Cloud PBX product Voxbi at https://voxbi.com. Compare identity options across the market on the provider comparison.

Frequently Asked Questions

❓ Can we mix SSO and standard logins?
Most Cloud PBX systems let SSO users and normal username-and-password users exist side by side. This helps during migration, and for external contractors who should not sit in your company directory. You can switch internal staff to SSO first and keep separate credentials for everyone else.
❓ What happens if our identity provider is unavailable?
If your provider is unreachable, SSO logins stop working. Better Cloud PBX vendors offer a fallback: a temporary local administrator account, or a backup authentication route. Confirm the emergency procedure before you commit, and note that calls already routed to desk phones usually keep working.
❓ Can we require two-factor authentication through SSO?
Yes, and this is one of the main reasons to use it. Two-factor authentication is enforced by your identity provider, not the phone system. A rule you set once in Microsoft Entra ID or Google Workspace applies to the PBX automatically, with no separate configuration.
❓ Does SSO work on mobile apps and desk phones?
SSO covers the web portal, the mobile app and the desktop softphone. Physical handsets and third-party clients usually still authenticate with SIP credentials, because SIP devices do not speak SAML. Ask which of your devices are covered.
❓ Is SSO included in every Cloud PBX plan?
No. It is often reserved for higher tiers or sold as an add-on, and some providers aimed at very small businesses do not offer it at all. Confirm both availability and price before signing, and check whether automatic provisioning is included or billed separately.

Related Features


📅 Not sure which features matter for your business?
Book a short call with a consultant and get a tailored recommendation.