Single sign on is a process that allows ShipStore to connect to your internal active directory server to authenticate users into the system, and assign permissions based on the user's group settings within Active Directory.

Note: SSO may not be available for hosted systems depending on how your Active Directory server is accessed. Please reach out to SS support for more info. SSO is not currently available in the public cloud system.


Enabling the Feature

To enable SSO in ShipStore, please contact our support team @ support@shipstore.com or through the "Submit a Request" link at the top or your page to begin this discussion. Depending on how your AD server is configured, we may have to coordinate some development/networking resources to ensure SS can connect.

Configuring for Active Directory

Connection Settings

Once enabled, you can begin configuring SS to connect to your AD server. 

Image Placeholder

Fill out the form above with the AD server connection information, as well as an admin user that can log in to AD and view users and groups within the AD tree. If you need, you can download AD Explorer on your SS server to test the settings.

Groups/Roles

The SSO connection also allows you to map roles within ShipStore to your internal groups. To create a mapping, click the blue plus button on the right-side of the Roles table, then enter your AD group name and select the SS role that group ties to. Once you do that, the next time a user in that group signs in, their permissions will be updated.

Test

Once the above is configured, you should be able to test this connection by logging out of the portal, then logging back in with an AD login with a group that is in the Roles table. If authenticated, SS will direct you to the appropriate landing page.

What SSO does not cover: the Merchant App

SSO signs users in to the Shipstore website. It does not log them into the Merchant App automatically when it opens. Users sign in to the Merchant App with the same Windows / Active Directory username and password, so there is no second set of credentials to manage.

Getting SSO set up

SSO uses your on-premises Active Directory and is enabled per site by Shipstore Development, so it is arranged rather than switched on. Email support@shipstore.com to start, and include the site you want it on and how your Active Directory is reachable. Support will scope the setup and any cost, then schedule a window with Development to connect the site to your AD server and test it.

What you should see when it is working: users sign in to the Shipstore website with their AD credentials and land on the right page for their role, and Merchant App sign-in accepts those same Windows / AD credentials.