Single Sign-On (SSO) in ServiceTitan

Prev Next
Core Product

Single Sign-On (SSO)

Let your team sign in to ServiceTitan using their Microsoft Entra credentials instead of a separate username and password — centralizing authentication through your organization's identity provider.

Setup

SSO lets users authenticate through Microsoft Entra ID instead of entering separate ServiceTitan credentials. ServiceTitan offers two configurations — Enterprise Hub SSO and Tenant-Level SSO — depending on how your organization accesses its tenants.

Setup checklist

Using Enterprise Hub? Set up SSO in Enterprise Hub first — users managed through Enterprise Hub can't be managed at the tenant level.

Manage Single Sign-On (SSO) in Enterprise Hub

Configure SSO for Enterprise Hub and the tenants it manages. If you use Enterprise Hub, start here.

Set up Single Sign-On (SSO) with Microsoft Entra ID (self-service)

Configure a tenant-level SSO connection and activate it.

Manage SSO users in ServiceTitan

Link existing ServiceTitan users to their SSO identity.

Sign in with Microsoft Entra ID

What end users see when signing in through SSO.

Feature status

Currently in Private Preview. Contact your Customer Success Manager (CSM) to enable SSO for your account.

SSO + MFA

SSO and MFA are separate. ServiceTitan requires MFA users with sensitive permissions. Satisfy it with your Entra MFA or your users will need to complete ServiceTitan's MFA.

Key workflows

Understand which SSO configuration applies to your organization before you begin setup.

Enterprise Hub SSO vs. Tenant-Level SSO

Choose the configuration that matches how your users access ServiceTitan tenants.

Using Enterprise Hub? Set up SSO in Enterprise Hub — see Manage Single Sign-On (SSO) in Enterprise Hub. Users managed through Enterprise Hub can't be managed at the tenant level.

Not using Enterprise Hub? You're in the right place — set up tenant-level SSO using the checklist above.

Legacy SSO vs. new self-service SSO

Classic Azure Active Directory customers must migrate to the new self-service SSO.

Troubleshooting & FAQ

Quick solutions to common issues and answers to frequently asked questions.

Troubleshooting

Step-by-step guides to resolve the most common issues.

Frequently Asked Questions

Which identity providers does SSO support?

ServiceTitan currently supports Microsoft Entra ID (formerly Azure Active Directory) only. Other identity providers are not supported at this time.

Does SSO replace multi-factor authentication (MFA)?

No — SSO and MFA are separate. SSO controls where you sign in; MFA is a second identity check that ServiceTitan requires whether or not you use SSO.

You can satisfy the MFA requirement with the MFA your organization enforces through Microsoft Entra — if your Entra MFA session is still valid, you won't be prompted again. Users with sensitive permissions may still need to complete ServiceTitan's own MFA.

For how ServiceTitan handles MFA, see Enforce Multi-Factor Authentication (MFA) for employees with sensitive permissions.

What happens to Classic Azure Active Directory (Legacy SSO) customers?

ServiceTitan will begin migrating customers off Classic Azure Active Directory starting November 2026. Your Customer Success Manager will reach out ahead of your migration window.

Is user provisioning via SCIM supported?

Not yet. SCIM-based user provisioning and deprovisioning is planned for a future release later this year. Until then, users must be created in ServiceTitan before they can be linked to an SSO connection.