Step 2 - Configuring your OneAdvanced Identity Organisation (Federated)

alethea.barlow@oneadvanced.com Updated by alethea.barlow@oneadvanced.com

Configuring your OneAdvanced Identity Organisation 

Before enabling OneAdvanced Identity in Time and Attendance you must ensure that you have configured your organisation within OneAdvanced Identity to reflect how you would like your employees and managers to login to the Time and Attendance web/mobile app.

Please note for federated users we recommend that you set the first login flow to 'automatic pairing - do not create user' against the provider tab, additional information can be found here.

Configuring your API Client

Time & Attendance synchronises users via APIs to Identity. By creating the API client, you will generate the Client ID and Client Secret that Time & Attendance needs to authenticate with the Identity APIs. To create your API Client ID and Client Secret, please follow the instructions detailed here. Once generated, this information should be entered into the Time & Attendance Identity onboarding screen as detailed in Step 3

    • Name (recommend “Time & Attendance”)
    • Type (set to confidential)
    • Grant types (set to client credentials)
    • Roles (User admin) Redirect URLs (not required - use client credentials only and ignore authorization code)
    • Owner email (customer contact details)
Single Sign on using Entra, Google Identity or similar (federated). 

Please refer to our Identity help section “federated authentication” for more information. This section will give you advice on setting up an Enterprise Application in your Microsoft Entra environment.  

Configuration is similar for Google Identity. 

If all your users use a federated login:

It is important to set the Federated only flag at organisation level to true. Please see here for further details.
It is recommended that the "Always use" is set to true in the Single sign-on provider details. The standard login screen (username and password) will then be bypassed.
When configuring Identity for Federated login, ensure that the configuration is set to automatic pairing - do not create user and not automatic pairing.

Was this article useful?

Step 1 - Requesting your OneAdvanced Identity Service (Federated)

Step 3 - Identity onboarding in Time and Attendance (Federated)

Contact