CINNOX allows you to activate third-party authentication (SSO) and use your Microsoft AD credentials to effortlessly log in to your CINNOX service. With OAuth integration and Microsoft Active Directory support, CINNOX ensures a secure and streamlined authentication process—a powerful combination that ensures a robust and hassle-free authentication process, granting you peace of mind and saving you valuable time. Elevate your login experience with CINNOX today.
CINNOX lets you set up Third-Party Authentication, allowing you and your fellow staff members to log in to the CINNOX service using an alternative method, such as your company network login credentials. This feature helps users minimise the instances they need to create, store, or remember multiple passwords, which may lead to data security issues if not properly managed.
📘
Important
CINNOX uses OAuth, an open standard for access delegation commonly used for the single sign-on (SSO) feature in websites or applications
To use Microsoft Active Directory Federation Services (AD FS), you must meet the following requirements:
- All users must have a CINNOX staff account.
- All users in your Active Directory instance must have an email address attribute.
- You have a server running Windows Server 2012 R2
Please ask your IT administrator to set up the SSO and bind with your CINNOX service login authentication.
📘
Please check this blog for the Step-by-step guide for the Windows AD FS 2012r2 Installation.
📘
You will need to sign to your CINNOX Web Dashboard with an admin staff account to enable the Third-Party Authentication and get the Resource and Redirect URLs.












<CINNOX Resource URL>, then click Add.




Before setting up your claims rule, ensure that your users' email addresses match their CINNOX email addresses. You can use other identifiers, such as the User Principal Name (UPN) if your UPNs are an email address.
For single sign-on with AD FS to work, the nameID needs to be in the form of an email address to match with a CINNOX user.


On the Configure Claim Rule screen
In the Mapping of LDAP attributes table, map the following:
Click Finish >



Format: Add-AdfsClient -RedirectUri "CINNOX Redirect URL" -ClientId "Name" -Name "Name"
Example: Add-AdfsClient -RedirectUri "https://darrenstore.cinnox.com/redirect.html" -ClientId "CINNOX" -Name "CINNOX"
Format: Set-AdfsRelyingPartyTrust -TargetName "Name" -EnableJWT true **Example**: Set-AdfsRelyingPartyTrust -TargetName **"CINNOX"** -EnableJWT true

Back to your CINNOX Web Dashboard:


Once the service-level third-party authentication is activated, Staff members will receive the system-generated message in their email and their Dashboard or App through a CINNOXBot message.
📘
Check your event viewer logs on your device for the error message if you receive an error when configuring the SSO. Contact CINNOX Support, If you are not able to troubleshoot the issue.
When a Staff administrator enables third-party authentication, you can use your Microsoft AD credentials to log in to the CINNOX service.
To view and manage third-party authentication, go to My Account > Authentication from the navigation menu.

🚧
If a Staff administrator disables service-level third-party authentication, you will not see this option.
To activate third-party authentication:


After successfully activating third-party authentication, the next time you log in to the CINNOX service, you may use the Sign in with Microsoft AD option on the login page.
📘
Refer to the App - Third-Party Authentication Guide for the detailed steps to configure and manage the authentication in the CINNOX App.
To deactivate third-party authentication:


Third-Party Authentication will change to Not Activated.
