Set default SSO provider
Admins can set an SSO provider as the default authentication method. With a default provider set, Prophix One automatically redirects users to that provider and not the standard Prophix login page where users continue to see the standard login page listing all available methods.
Considerations for organizations with multiple SSO providers
Organizations with more than one SSO provider configured should keep Prophix Authentication as the default. This preserves the full login page, allowing users to choose the provider that applies to them. Setting a single SSO provider as the default redirects all users to that provider automatically, removing their ability to choose.
Set an SSO provider as the default authentication method
Before proceeding, ensure that the following prerequisites are met.
-
Portal Administrator permissions.
-
An SSO method (OIDC 1.0 or SAML 2.0) already configured in SSO and Authentication. See Manage authentication.
-
At least one Portal admin account with Prophix Authentication assigned in addition to an SSO method, so the emergency recovery URL remains usable during an IdP outage.
To set a default SSO provider:
-
In the left-hand panel, click Account Management > SSO and Authentication.
-
Select the SSO method to set as default.
-
Under Default Authentication, turn on the toggle.
-
Confirm your action. A dialog appears displaying the emergency recovery URL, a description of what it does, and options to copy or download the information.
-
Save the emergency recovery URL in a secure location outside of Prophix One before dismissing the dialog.
From this point on, users who navigate to Prophix One are automatically redirected to the default SSO provider.
Emergency recovery URL
Once an SSO provider is set as default, auto-redirect means admins can no longer reach the standard login page directly. To guard against Identity Provider (IdP ) outages, Prophix One provides an emergency recovery URL that bypasses the redirect and lets a Portal admin sign in using Prophix Authentication.
The URL appears in three places in the Portal UI:
-
The window displayed when the default authentication method is switched to an SSO provider (includes copy/download options)
-
The SSO method detail panel, when viewing the provider currently set as default
-
The Account Information page, when SSO is set as the default method
Best Practice: Copy or download the emergency recovery URL as soon as an SSO provider is set as default, and store it outside Prophix One (e.g., in a password manager or secure document). You will need it if the IdP becomes unavailable.
Access the emergency recovery URL later
If the emergency recovery URL needs to be retrieved after initial setup:
-
From the SSO method detail panel: In SSO and Authentication, select the row of the default SSO provider. The emergency recovery URL appears at the bottom of the detail panel.
-
From Account Info: Navigate to the Account Info page. If SSO is set as the default, the emergency recovery URL is shown therefor you to copy..
Use the emergency recovery URL during an IdP outage
If the SSO provider is unavailable and users are being redirected away from Prophix One:
-
Open the emergency recovery URL in a browser. The standard Prophix One sign-in page appears, bypassing the auto-redirect.
-
Sign in with Prophix Authentication credentials.
Once signed in, take remediation steps — such as temporarily reassigning Prophix Authentication to affected users — until the IdP is restored.
Note: The emergency recovery URL does not change the SSO configuration or affect other users. It only suppresses the auto-redirect for the session initiated through that URL.
Revert to Prophix Authentication as the default
To disable the auto-redirect and return to the standard Prophix One login page for all users:
-
In SSO and Authentication, select the row for Prophix Authentication.
-
Under Default Authentication, turn on the toggle.
-
Confirm your action.
Users see the full login page with all authentication methods listed on their next sign-in.
Troubleshooting
Users are not being auto-redirected after the change
Confirm the SSO method is set as the default under Default Authentication in SSO and Authentication. It may take a moment for the change to propagate.
Some users are being redirected to the wrong SSO provider
The organization likely has multiple SSO providers configured. Set Prophix Authentication as the default so users can select their own provider at sign-in.
Emergency recovery URL was not saved and is no longer visible
Open the SSO method detail panel or the Account Info page — the URL is available for copying from both locations.
Emergency recovery URL does not bypass the redirect
Confirm the full URL is entered correctly with no extra characters. Clear browser cookies and try again in a private or incognito window.