How to set up and enforce SSO or MFA in Q-Cal

How to set up and enforce SSO or MFA in Q-Cal

Purpose

SSO allows users to log in to Q-Cal using their existing Google or Microsoft account. This improves security and reduces the need for separate passwords.

Supported SSO providers
  1. Google
  2. Microsoft

Alert
To enable SSO login, an enterprise licens is required!

How to enforce SSO or MFA (or both)

  1. Navigate to Generel Settings: Press on user profile > Admin Settings > Generel Settings.


  2. Find the MFA and Authentication policies, and choose the desired login policies:


Overall authentication policy

  1. Optional: Users may choose to login and use Single-SignOn (SSO) or Multi-Factor Authentication (MFA) on their own account.
  2. Mandatory for all: All users must at least log in and use Single-SignOn (SSO) or Multi-Factor Authentication (MFA).
  3. Optional for groups: Users may choose to use MFA if they wish to.
  4. Deactivated for all: Deactivates MFA for the whole account.

MFA (Pin code) Policy

  1. Mandatory: All users must use MFA as part of the login process.
  2. Deactivated for regular users: MFA is deactivated for all users except administrators.
  3. Optional for groups: It is offered as a possibility for our Enterprise Customers to enforce Single-SignOn (SSO) or Multi-Factor Authentication (MFA) on specific client groups.

Reset MFA Pin for a user

If a user has forgotten or lost their authenticator, you (as administrator) can reset their MFA Pin. Go to "Admin" -> "User profiles" and click the padlock icon.

This will result in the user having to set up their PIN again on next login.




Setting up SSO

Info
No setup is required in Entra when using Microsoft.
To allow your users to log in with SSO, you first need to set this up on your clients (When Enterprise licens is active, you have to create a client to be able to create a user. Meaning that the client and user is linked together in the backend.)

  1. Go to your client settings, by pressing on the Main Menu button, and the selecting clients.


  2. You can then set up the SSO login on a whole group. To set up a group, press on the group name, a new pop-up will now open.


    1. Once in the new pop-up, enter the domain of your mail environment, ex. "JohmDoe@Nordicscreen.com" - here the domain is "Nordicscreen.com".
    2. If you chose the option, "Optional for groups", you can also choose what the groups requirement to log in is.
  3. Once these steps is complete, you are now ready to log in using SSO.