Brightest
  • πŸ‘‹Welcome to Brightest
  • Overview
    • πŸ’‘Brightest 101
    • πŸ”…New Client Onboarding Sequence
    • ✨Key Brightest Capabilities
  • Fundamentals
    • πŸ› οΈGetting set up
      • πŸ‘©β€πŸ’ΌGetting Started for Brightest Admins
      • πŸ“User Permissions
      • πŸ“¨Inviting Team Members
        • πŸ”‘Two-Factor Authentication
      • πŸ–ΌοΈOrganization Settings
        • πŸ“ΆESG and Sustainability Settings
      • πŸ”“Single Sign-on (SSO)
        • πŸ‡«πŸ‡²Microsoft SSO
        • πŸ‡«πŸ‡²Okta SSO
    • πŸ“‹Navigating Brightest
  • Product Guides
    • πŸ“ŠKPIs and Custom Metrics
      • ℹ️Creating a KPI
      • ℹ️Linking KPIs to Global licenses
      • πŸ—‚οΈOrganizing your KPIs
        • KPIs & Global licenses
      • πŸ’»Entering KPI data
    • 🎯Goals and Targets
      • β›³Setting Goals
      • Uploading Data to Goals
      • πŸ“‰Setting Environmental or Climate Related Targets
      • πŸ“ŠMateriality (single)
    • βš–οΈDouble Materiality
      • 🌐Double Materiality in Brightest
    • 🌎CSR & Impact
    • ⚑Actions
    • πŸ“₯Surveys
      • πŸ“‘How to make a survey
        • Survey form features
    • πŸ‘₯Partners
    • 🏒Assets
      • πŸ—οΈBulk Asset Creation
    • ☁️Carbon Accounting
      • πŸŒ₯️How Carbon Accounting Works in Brightest
      • βž—Emissions Factors
      • πŸ‘©β€πŸ”¬Configuring and Customizing Emissions Factors
      • 1️⃣Scope 1 GHG
      • 2️⃣Scope 2 GHG
      • 3️⃣Scope 3 GHG
    • 🌿Collecting and Importing Sustainability Data
      • πŸ‘£Uploading Asset Footprint Data
        • Using the Add Tool
          • Adding Water Data
          • Adding Fuel Data
          • Adding Waste Data
        • Uploading CSV Files
        • Uploading Utility Invoices
      • πŸš›Uploading Transit Data
      • πŸ’±Financial Transaction (Spend) Data
        • πŸ’ΈSpend Capabilities
      • πŸ›οΈProduct and Materials Data
    • 🚩Tags
    • πŸ“ESG & Sustainability Reporting
      • ESG Reporting Standards & Frameworks in Brightest
  • Use Cases
    • 🏭GHG Emissions Measurement
    • πŸ–₯️Brightest for IT Teams
  • Roadmap
    • πŸ”†Our Product Roadmap
  • FAQs and Support
    • ❓FAQs
    • πŸ“§Contact Us
Powered by GitBook
On this page
  1. Fundamentals
  2. Getting set up

Single Sign-on (SSO)

Accessing Brightest and authenticating with your organization's directory or identity provider (IDP)

PreviousESG and Sustainability SettingsNextMicrosoft SSO

Last updated 1 year ago

Brightest supports secure single sign-on (SSO) access through a variety of identity providers (IDPs), including Microsoft Azure Active Directory, Google, and Okta. Brightest SSO is implemented using Open ID Connect (), a simple identity layer on top of the OAuth 2.0 protocol that allows Clients to verify the identity of the End-User based on the authentication performed by an Authorization Server, as well as to obtain basic profile information about the End-User in an interoperable and REST-like manner.

To implement SSO with your Brightest account:

  1. Confirm with your IT department which SSO IDP your organization uses, and share that information with your Brightest relationship lead. Note: SSO set up, testing, and configuration requires an additional one-time implementation fee.

  2. Provide Brightest with a list or directory export of your Brightest account users within your Brightest onboarding questionnaire. Include (a) first name, (b) last name, (c) email, and (d) desired user role for each primary account user or admin.

  3. During your Brightest implementation, Brightest will create an SSO Group for your organization and users based on the onboarding information or directory export you provide. Typically this process takes 1-2 weeks, depending on the size and complexity of your SSO Group directory.

  4. During implementation, Brightest will map SSO identities to your designated Brightest SSO group and user directory, allowing your team to access Brightest through secure Oauth 2.0 authentication with their designated identity account. During the validation phase, you’ll be able to confirm SSO is working correctly before proceeding with end-user training.

  5. If you need to adjust user roles and permissions, Brightest account admins can perform these changes within your account (), or you can change user roles and permissions programmatically using Brightest’s API and the OrgRole endpoint.

For more questions or to discuss Brightest SSO further, please contact your Brightest account representative. Our team is happy to meet with your IT department to confirm your requirements and optimal SSO set up approach.

πŸ› οΈ
πŸ”“
https://openid.net/connect
https://www.brightest.io/manage/team/