What do I need to know?

alethea.barlow@oneadvanced.com Updated by alethea.barlow@oneadvanced.com

How do I enable Identity? 

Implementing Identity is very straightforward. However, there are several pre-requisites you need to ensure you meet, and several configuration steps you will need to follow to enable Identity. This document aims to guide you through that process. 

The user process 

Time and Attendance will synchronise user data to Identity. This process will ensure that every unique email address held against an employee or manager has a user account in Identity. If “Use employees without email address” is enabled, then all employees and managers will be synchronised, including those without email address, see employees without email addresses here. The following data is synchronised: Name, email address, and employee number. Synchronisation is via API.

Once a user is synchronised with Identity they will receive a welcome email guiding them through the new login experience. You can control when that email is sent, and the content of the email via the Identity Organisation module. This is explained further later in this guide. 

If the email address in Time and Attendance matches an existing Identity user record, then the Time and Attendance record will be linked to that record, rather than creating a new user record in Identity. 

Identity pre-requisites

Before enabling Identity the following checklist should be completed. This will ensure that you and your users are prepared for the changes enabling Identity will have on your system as well as ensuring your employee and manager data is appropriate for syncing with Identity. 

  • You need to ensure you are on the latest version of Time and Attendance. If you are unsure whether this is the case or not, please contact support.
    • To identify the version of Time and Attendance you are on: 
      • for Web access, login as a manager and select “About”.  
      • For WinTMS access, select “Help” then “About”.  
      Releases are normally every 2 to 3 months, so check the build date is within that timeframe: 
             
      A screenshot of a computer
          
          AI-generated content may be incorrect.
  • You are a Time and Attendance system administrator. 
  • You are a customer administrator for Identity. 
  • If you are using Microsoft Entra, Google Identity or similar for a federated Single Sign-On experience, you must have administration access to that platform. 
  • You have determined if you need federated users, non-federated users or both. Choosing your authentication method information can be found here.
  • You have reviewed the dedicated Identity Service guidance available here, to understand more about the authentication features and functionality available. 
  • All Employee and manager records in time and attendance should have a unique email address (unless you have enabled users without email address and “Allow sync without email” is enabled. Please be aware that where you have linked an employee record to a manager record, the employee’s email address will be shared with the manager. The email address does not have to be an organisations email address (it can be a personal email address if required). 
    • For employees who will NEVER log into a OneAdvanced system, such as time and attendance or the mobile app (but who may clock via a Smart Biometric Clock), the email address is not mandatory (see “Employees without email addresses” here). 
    • For employees where you do not hold an email address, it is possible to enable login through Identity. There are certain limitations you need to be aware of, and they are set out in “Employees without email addresses” here
    • For those employees and managers with an email address, this email address MUST be unique across all records within time and attendance. Unique email is mandated once Identity is enabled. 
  • An individual employee record should not be linked to more than one manager, as this will prevent synchronisation to Identity. 
  • All employees and managers MUST have a unique email address. This is mandated once Identity is enabled. 
  • Email addresses must follow a valid email format (e.g. does not contain spaces). 
  • Any manager records that no longer require Time and Attendance access should be marked as Inactive. 

Don't worry! The Time and Attendance Identity Onboarding function will perform these email checks for you and let you know which employee/manager records are affected.  

Understanding the changes 

Below is a summary of the key changes when enabling Identity: 

  • Users will be directed to the Identity login page for your organisation, instead of a Time and Attendance login page. 
  • Once enabled, all current users’ credentials will be changed upon first accessing the Time and Attendance web/mobile app. 
  • There is no change in the way employees and managers are created in Time and Attendance. The integration between Identity and Time and Attendance works in the background via API, to synchronise them to their Identity accounts. 

Depending on the method used to authenticate with Identity, please refer to the relevant section of the Identity help guide:

Non-federated login with authenticator app 

Non-federated login with email 

Federated login 

  • Identity supports biometric authentication for users that have authenticated via “EasyPass”. Please see User Journey for EasyPass for more information. 
  • By consolidating employee and manager accounts, switching between the two personas will be quicker and easier. You will be able to switch between profiles at the click of a button within the dashboard. 

Was this article useful?

Employees without email addresses

Managing Identity

Contact