Manage SSO users in ServiceTitan

Prev Next

Overview

After your SSO connection is active, use the SSO user management screen to link and manage your users' Entra identities. Users must exist in ServiceTitan before you can link them.


Who uses this feature

  • Tenant Administrators

  • Applies to all business types

  • Applies to all trades

Feature configuration

This feature is currently in Private Preview and available for specific accounts. It is subject to change. To enable it for your account, contact your Customer Success Manager (CSM).

Things to know

  • Link users in Go only. Links propagate to Next automatically.

  • Auto-link works once per Entra identity across all ServiceTitan tenants. Link additional ServiceTitan profiles manually.

  • Enterprise Hub-managed users appear read-only and are managed in Enterprise Hub.

  • Unlink deletes the stored Entra data. Use Disable to pause SSO and keep the link.

  • ServiceTitan sets the login policy. Request changes through your CSM or a support ticket.

  • Keep a ServiceTitan username and password as backup during the transition.

Go to SSO user management

  1. Go to Settings.

  2. In the side panel, go to Security > Single Sign-On.

This screen lists all users and their current SSO status. You can:

  • Search by name, username, or email.

  • Filter by Enabled, Disabled, or Not Linked.

  • Export the user list to CSV.

User accounts listed for Single Sign-On configuration with their statuses and details.

Use status indicators

  • Enabled (green): The user is linked to an Entra identity and SSO is active for their account.

  • Disabled (red): The user is linked but SSO login has been turned off for their account.

  • Not Linked (gray): The user has not been linked to a Microsoft Entra identity.

Make sure connections are Active in every environment your users need. If Next has no connection, linked users cannot sign in to Next with SSO. Set up the Next connection in Settings > Integrations > Single Sign-On first.

Enterprise Hub users

Some users may be managed by Enterprise Hub SSO. They appear read-only and cannot be changed here. Manage them in Enterprise Hub > User Management > Security. If a user should be editable, check with your Enterprise Hub administrator.

There are two ways to link users: manually, or with auto-link at first sign-in.

Use manual linking for rollout, testing, or specific users.

  1. Find the user in the list.

  2. Click More (⋯) next to the user, then click Link. User management interface for configuring Single Sign-On with user details and statuses.

  3. Select the SSO connection. User selection interface for linking accounts in ServiceTitan's Single Sign-On feature.

  4. Enter the user's Microsoft Entra Object ID. Find it in the Microsoft Entra admin center under Users > [the user] > Overview. User selection interface for linking accounts in ServiceTitan's Single Sign-On feature.

  5. Confirm to finish. The user's status changes to Enabled. User linking interface showing Mikey Nelson's details and options to link users.

When linked, the user's status updates to Enabled.

Auto-link lets users link their own accounts the first time they sign in with Microsoft Entra ID — no admin linking required. It's recommended for larger organizations. Auto-link is off by default; an admin turns it on per connection.

Enable auto-link (admin):

  1. Go to the top toolbar and click Settings.

  2. In the side panel, go to Integrations > Single Sign-On.

  3. Select the connection, then turn on Enable Auto Linking.

What the user does at first sign-in:

  1. The user clicks Sign in with Microsoft Entra ID on the login screen. The Classic option does not start auto-link. Sign in page for ServiceTitan with options for username and Microsoft Entra login.

  2. The user signs in with Microsoft. Microsoft sign-in page for Microsoft Entra with options for GitHub and 1Password.

  3. ServiceTitan asks them to confirm linking with their ServiceTitan credentials. This happens once. Instructions to link ServiceTitan account with Microsoft Entra ID for secure access.

  4. Their accounts link permanently. Future logins use SSO. Sign-in page for linking Entra account to ServiceTitan with promotional email preview.

Note: Auto-link works once per Entra identity across all ServiceTitan tenants. Link any other profiles manually with the Object ID.

Note: Auto-link runs only in Go. Send users to go.servicetitan.com to auto-link first; access to Next follows automatically.

Users with multiple profiles

One Entra identity can link to several profiles. For example, a user with an office account and a technician account can use one Entra login for both. After sign-in, the profile switcher lets them choose a profile without signing out.

Note: Auto-link applies only to the first profile linked to a Microsoft Entra identity (see Auto-link above). Any additional profiles must be linked manually by an admin using the user's Entra Object ID.

Profile selection screen in ServiceTitan with various service company options displayed.

Note: In the Field Mobile App, technicians pick a profile at sign-in. To switch, they must sign out and sign back in.

Go to Settings > Security > Single Sign-On, click More (⋯) next to a linked user, then click Connection Details.

  • Sign in with SSO: turn this off to disable SSO for the user. They sign in with their ServiceTitan username and password. The Entra link stays and can be re-enabled.

  • Unlink: remove the Entra link entirely. The stored Entra data is deleted. Re-linking requires the Object ID again.

Connection details for Single Sign-On, including user information and connection name.

Keep backup access

Have all users keep an active ServiceTitan username and password alongside SSO. If SSO is paused, such as during Entra maintenance, users without backup credentials cannot sign in. Confirm users can sign in with their password before you fully switch to SSO.

SSO login policy

ServiceTitan sets the login policy for your tenant. You cannot change it in settings. Request a change through your CSM or a support ticket.

Policy

Linked users

Unlinked users

SSO If Linked (default)

Must use SSO

Use username and password

Mixed

SSO or password

SSO or password

SSO Only

Must use SSO

Locked out until an admin restores access

Caution: Turn on SSO Only only after every user is linked. Any unlinked user is locked out until an administrator restores access.

Export SSO users

  1. Go to Settings > Security > Single Sign-On.

  2. Click Export in the upper right.

The CSV includes: Name, Username, Email, Connection Name, Connection Status, Protocol, and External ID (Entra Object ID).

User accounts listed with SSO status and search functionality for management.

MFA and SSO

Your Microsoft Entra administrators manage MFA. ServiceTitan does not enforce it separately. If a user's Entra MFA session is valid, they are not prompted again. Users should complete MFA with Microsoft before they sign in with Microsoft.

Want to learn more?