Please enable JavaScript to view this site.

Navigation: Support

Signing in with single sign-on (SSO)

Scroll Prev Top Next More

Single Sign-On (SSO) and user provisioning (SCIM) are available with GraphPad Enterprise and Organization plans. Learn More...

If your organization manages accounts through an identity provider, you can sign in to Prism using single sign-on rather than a separate GraphPad password. Your identity is verified once by your organization's identity provider, and Prism receives a signed token confirming who you are.

Prism supports the two standards used by enterprise identity providers: SAML 2.0 and OIDC (OpenID Connect). SSO is available on both Windows and Mac.

Signing in

When you choose to sign in with SSO, Prism opens the sign-in page in your computer's default web browser rather than inside the Prism window. Complete the sign-in there, including any multi-factor authentication your organization requires, and then return to Prism. Prism finishes activation automatically once your browser confirms the sign-in.

Signing in through your regular browser has a practical advantage: the browser already carries your organization's device registration and compliance state. If your organization enforces conditional access or device compliance policies, those checks can be satisfied in the browser, which avoids activation failures that can occur when signing in inside an application window.

Staying signed in

Once activated, Prism stores an activation token locally so you do not need to sign in each time you launch the program. Prism periodically confirms your license with the licensing server. If the server reports that your activation is no longer valid, for example because the seat was released by an administrator, Prism removes the stored token and you will be asked to sign in again.

To sign out of Prism or free the seat for use on another computer, use the deactivation option in Prism's preferences. After deactivating, you can activate again with a different account or a different license.

For administrators

SSO is configured by an administrator on the GraphPad side, not within Prism itself. GraphPad publishes step-by-step setup guides for the following identity providers:

Microsoft Entra ID (SAML and OIDC)

Okta

OneLogin

JumpCloud

Shibboleth

Providers that are not listed generally follow a similar configuration process. Directory synchronization through SCIM can also be configured, so that user accounts are provisioned and deprovisioned automatically from your directory.

For the provider guides, video walkthroughs, and SCIM setup instructions, see SSO and SCIM identity provider guides.

If sign-in does not complete

Confirm that the sign-in finished successfully in the browser window that Prism opened, and that you returned to Prism afterward.

Check that your computer can reach the internet, and that a firewall or proxy is not blocking the connection.

If your organization enforces device compliance, confirm with your IT administrator that this computer is registered and compliant.

If your organization does not have an Enterprise or Organization plan, or has not configured SSO, sign in with your GraphPad account credentials or activate with a serial number instead. See support and license information.

 

© 1995-2019 GraphPad Software, LLC. All rights reserved.