Set Up Single Sign-On
Administrator access on Peakon.
If your employees have email addresses from multiple domains, you need to specify them on your organization's account for single sign-on (SSO) to work. Contact Customer Care for assistance.
You can set up SSO so your employees can sign into Peakon using their credentials from your identity management tool. Example: Okta. See Concept: Single Sign-On for more information.
Peakon is deprecating the legacy app.peakon.com domain and replacing it with a unique subdomain per customer. Ensure that your SSO configuration reflects your organization's subdomain before August 2024. See more: Workday Peakon legacy domain retirement.
- Enable SSO in Peakon.
- Go to .
- ClickConnect. The page will now display SSO configuration fields.
- EnterSSO Log-in URL.
- Copy theEntity IDandReply URL (ACS)values, then enter them in the tool that you will use for SSO.
- (Optional) EnterSSO Log-out URL.
- UploadCertificate.
- Select an option in theRequire single sign-ondrop-down menu.
- (Optional)Force authenticationto require anyone signing in to go through SSO, even if they have an active session.
- (Optional)Force legacy domainif you need to use the legacy domain app.peakon.com for the redirect URL. Note that when using this setting, theEntity IDandReply URLsettings won't update, but the functionality will work as intended.This setting provides easier adoption of subdomains for customers who use Okta or other SSO providers that don't allow multiple callback URLs. See this article for more details: Workday Peakon legacy domain retirement.
- Test SSO:
- Sign out of Peakon, then sign back in using your work email address and continue.
- Peakon should redirect you to the SSO page in your identity management tool, then redirect back to Peakon.