Overview
After your SSO connection is active, use the SSO user management screen to link and manage your users' Entra identities. Users must exist in ServiceTitan before you can link them.
Who uses this feature
Tenant Administrators
Applies to all business types
Applies to all trades
Feature configuration
This feature is currently in Private Preview and available for specific accounts. It is subject to change. To enable it for your account, contact your Customer Success Manager (CSM).
Things to know
Link users in Go only. Links propagate to Next automatically.
Auto-link works once per Entra identity across all ServiceTitan tenants. Link additional ServiceTitan profiles manually.
Enterprise Hub-managed users appear read-only and are managed in Enterprise Hub.
Unlink deletes the stored Entra data. Use Disable to pause SSO and keep the link.
ServiceTitan sets the login policy. Request changes through your CSM or a support ticket.
Keep a ServiceTitan username and password as backup during the transition.
Go to SSO user management
Go to Settings.
In the side panel, go to Security > Single Sign-On.
This screen lists all users and their current SSO status. You can:
Search by name, username, or email.
Filter by Enabled, Disabled, or Not Linked.
Export the user list to CSV.

Use status indicators
Enabled (green): The user is linked to an Entra identity and SSO is active for their account.
Disabled (red): The user is linked but SSO login has been turned off for their account.
Not Linked (gray): The user has not been linked to a Microsoft Entra identity.
Confirm your connections before you link
Make sure connections are Active in every environment your users need. If Next has no connection, linked users cannot sign in to Next with SSO. Set up the Next connection in Settings > Integrations > Single Sign-On first.
Enterprise Hub users
Some users may be managed by Enterprise Hub SSO. They appear read-only and cannot be changed here. Manage them in Enterprise Hub > User Management > Security. If a user should be editable, check with your Enterprise Hub administrator.
Link a user
There are two ways to link users: manually, or with auto-link at first sign-in.
Link a user manually
Use manual linking for rollout, testing, or specific users.
Find the user in the list.
Click More (⋯) next to the user, then click Link.

Select the SSO connection.

Enter the user's Microsoft Entra Object ID. Find it in the Microsoft Entra admin center under Users > [the user] > Overview.

Confirm to finish. The user's status changes to Enabled.

When linked, the user's status updates to Enabled.
Set up auto-link
Auto-link lets users link their own accounts the first time they sign in with Microsoft Entra ID — no admin linking required. It's recommended for larger organizations. Auto-link is off by default; an admin turns it on per connection.
Enable auto-link (admin):
Go to the top toolbar and click Settings.
In the side panel, go to Integrations > Single Sign-On.
Select the connection, then turn on Enable Auto Linking.
What the user does at first sign-in:
The user clicks Sign in with Microsoft Entra ID on the login screen. The Classic option does not start auto-link.

The user signs in with Microsoft.

ServiceTitan asks them to confirm linking with their ServiceTitan credentials. This happens once.

Their accounts link permanently. Future logins use SSO.

Note: Auto-link works once per Entra identity across all ServiceTitan tenants. Link any other profiles manually with the Object ID.
Note: Auto-link runs only in Go. Send users to go.servicetitan.com to auto-link first; access to Next follows automatically.
Users with multiple profiles
One Entra identity can link to several profiles. For example, a user with an office account and a technician account can use one Entra login for both. After sign-in, the profile switcher lets them choose a profile without signing out.
Note: Auto-link applies only to the first profile linked to a Microsoft Entra identity (see Auto-link above). Any additional profiles must be linked manually by an admin using the user's Entra Object ID.

Note: In the Field Mobile App, technicians pick a profile at sign-in. To switch, they must sign out and sign back in.
Disable or unlink a user
Go to Settings > Security > Single Sign-On, click More (⋯) next to a linked user, then click Connection Details.
Sign in with SSO: turn this off to disable SSO for the user. They sign in with their ServiceTitan username and password. The Entra link stays and can be re-enabled.
Unlink: remove the Entra link entirely. The stored Entra data is deleted. Re-linking requires the Object ID again.

Keep backup access
Have all users keep an active ServiceTitan username and password alongside SSO. If SSO is paused, such as during Entra maintenance, users without backup credentials cannot sign in. Confirm users can sign in with their password before you fully switch to SSO.
SSO login policy
ServiceTitan sets the login policy for your tenant. You cannot change it in settings. Request a change through your CSM or a support ticket.
Policy | Linked users | Unlinked users |
|---|---|---|
SSO If Linked (default) | Must use SSO | Use username and password |
Mixed | SSO or password | SSO or password |
SSO Only | Must use SSO | Locked out until an admin restores access |
Caution: Turn on SSO Only only after every user is linked. Any unlinked user is locked out until an administrator restores access.
Export SSO users
Go to Settings > Security > Single Sign-On.
Click Export in the upper right.
The CSV includes: Name, Username, Email, Connection Name, Connection Status, Protocol, and External ID (Entra Object ID).

MFA and SSO
Your Microsoft Entra administrators manage MFA. ServiceTitan does not enforce it separately. If a user's Entra MFA session is valid, they are not prompted again. Users should complete MFA with Microsoft before they sign in with Microsoft.