Navigation

10.18. Set Up SSO with Keycloak, Google Workspace, or Microsoft 365

Configure staff SSO with your Keycloak realm in Community or Enterprise Edition, or link Google Workspace and Microsoft 365 accounts in Enterprise Edition.

10.18. Set Up SSO with Keycloak, Google Workspace, or Microsoft 365
Configure staff SSO with your Keycloak realm in Community or Enterprise Edition, or link Google Workspace and Microsoft 365 accounts in Enterprise Edition.
10. SettingsUpdated: 10/8/2026

Single Sign-On (SSO) Management

Single Sign-On allows users to log in to AlgaPSA using their existing credentials from Keycloak, Google Workspace, or Microsoft 365. This lets an MSP use its staff identity provider for daily PSA access. Administrators configure SSO from Settings > Security > Single Sign-On.

Availability: Keycloak is available in Community Edition and Enterprise Edition and is the SSO option in Community Edition. Google Workspace and Microsoft 365 SSO require Enterprise Edition.


Configure Keycloak (OpenID Connect)

Use your own Keycloak realm to authenticate existing internal users. Users are matched by email to their AlgaPSA accounts; Keycloak sign-in does not create users. Before setup, create the staff accounts in AlgaPSA and confirm that their email addresses match their Keycloak identities.

Figure 1: The Keycloak card under Security > Single Sign-On.

  1. Open Settings > Security > Single Sign-On and find Keycloak / OpenID Connect.
  2. Create a confidential OpenID Connect client in your Keycloak realm and allow the redirect URI displayed in AlgaPSA.
  3. Complete these fields:
FieldWhat to enter
Keycloak server URLThe public server URL, for example https://keycloak.example.com. Enter the realm separately.
RealmThe realm name exactly as it appears in Keycloak.
Client IDThe ID of the confidential client created for AlgaPSA.
Client secretThe client's secret. On later edits, leave it blank to keep the saved secret.
  1. Select Verify and save. AlgaPSA checks the realm's OpenID discovery endpoint and verifies its issuer before saving. The issuer combines the server URL and realm, for example https://keycloak.example.com/realms/northpoint.
  2. Expand Advanced: custom identity provider routing and add your staff login domain. In Enterprise Edition, claim and verify that domain; Community Edition uses domain registration without ownership verification.
  3. Test sign-in with an existing staff member's email address. The Keycloak button appears only when provider discovery succeeds and returns Keycloak for that login. If it does not appear, review the saved realm configuration and login-domain routing.

Check that the test opens the intended staff account. Keep password-based access available while validating the realm and email matching.

Figure 2: Once discovery succeeds, Sign in with Keycloak appears on the sign-in page beside the other providers.


Link Google or Microsoft SSO from Your Profile

In Enterprise Edition, individual users can link their AlgaPSA account to Google or Microsoft directly from their profile settings.

Steps to Link Your Account

  1. Click on your profile avatar in the top right corner of AlgaPSA.
  2. Select Profile from the dropdown menu.
  3. Navigate to the Single Sign-On tab.
  4. In the Secure your account with SSO section:
    • Confirm your email address shown in the Signed in as field.
    • Enter your Current password.
    • Click the Verify Credentials button.
  5. Once verified, a message will appear: "Credentials verified. Choose a provider below to finish linking your account."
  6. In the Connect a provider section, click on your desired provider:
    • Google Workspace - Sign in with your Google-managed identity.
    • Microsoft 365 (Azure AD) - Sign in with your Azure Active Directory account.
  7. You will be redirected to your provider's login page. Select or sign in with the account you want to link.
  8. After successful authentication, you will be redirected back to AlgaPSA.
  9. Your linked account will appear in the Linked accounts section, showing:
    • The provider badge (Google or Microsoft)
    • Your linked email address
    • The date the account was linked
    • The last time SSO was used
  10. Click Save Changes to finalize the setup.

Administrator SSO Management in Enterprise


Navigate to Settings > Security, then open the Single Sign-On tab in Security Settings. This section is for administrators to configure providers, link or unlink existing users, and manage SSO behavior in AlgaPSA.


Single Sign-On Assignment (Linking and Unlinking Existing Users)

Steps to Link Users

This process is used to connect existing internal users to your configured SSO provider.

  1. Under the Single Sign-On Assignment section, locate the Choose provider toggle
  2. Select your provider by clicking on the corresponding tab: Google Workspace or Microsoft 365 (Azure AD).
  3. Ensure the Action toggle is set to Link selected users.
  4. In the Find internal users search bar, you can search for users by their email.
  5. Check the box next to the user(s) you want to link. You can select multiple users.
  6. (Optional): Click Preview assignment to review the actions before execution. It will display below the list of users.
  7. Click the Link accounts button to finalize the SSO assignment for the selected users.

Steps to Unlink Users

Unlinking a user returns their account to their original password-based sign-in method.

  1. Under the Single Sign-On Assignment section, select your provider (Google Workspace or Microsoft 365).
  2. Change the Action toggle to Unlink selected users.
  3. In the Find internal users section, find and check the box next to the user(s) you wish to unlink.
  4. (Optional): Click Preview unlink to review the actions before execution. It will display below the list of users.
  5. Click the Unlink accounts button to remove the SSO link for the selected users.

Automatically Set Up SSO for New Users

This setting ensures that any new internal staff member added to AlgaPSA after this feature is enabled will be automatically provisioned for SSO if their email matches a configured provider.

  • To enable this feature, locate the setting Automatically set up SSO for new internal users.
  • Toggle the switch to the ON position (it will turn purple).

Previewing Assignment

The preview function is highly recommended when processing multiple users to avoid unintended changes.

  1. Select your Provider and the desired Action (Link or Unlink).

  2. Select the user(s) from the internal user list.

  3. Click the Preview assignment (or Preview unlink) button.

  4. A Preview results section will appear below the user list, detailing:

    • Processed Users: The total number of selected users.
    • Linked/Unlinked: How many accounts will have the action applied.
    • Already Linked/Unlinked: How many accounts already have the desired status and will be skipped.
    • Skipped (Inactive): Accounts that cannot be processed (e.g., inactive users).

Related identity features

This page covers SSO for your own internal AlgaPSA users, including email matching through Keycloak. Client access and automated user lifecycle management are separate workflows: