Short answer:
You can enable Single Sign-On (SSO) for an Account Admin by linking their Xink account to Entra ID (Azure AD). Once linked, the admin can log in using their Microsoft credentials.
This requires that SSO (OpenID/OAuth) is already configured and enabled in your Xink account.
Step 1: Enable external authentication
- Click the gear icon or go to Preferences.
- Open Security under the General tab.
- Enable "Allow External Authentication".
- Click Save.

Prerequisite
SSO must already be configured in Entra ID (Azure AD) using OpenID or OAuth.
Step 2: Link the Account Admin to Entra ID
- Log in using the Account Admin you want to link.
- Click your name and open Logon Options.
- Click the Link Azure AD Account.
- Sign in with your Microsoft (Entra) ID credentials.
- Log out and log back in using the Microsoft sign-in option.





Once linked, the option will change to Unlink Azure AD Account, confirming that SSO is active.
Optional: Force SSO for all admins
You can enforce SSO for all admins by enabling the Force Azure AD Open ID option.
This will:
- Disable login using Xink username/password
- Require all admins to sign in using Microsoft credentials

Important
Ensure all admins are in Entra ID before enabling this setting, or they will not be able to access the Xink portal.
Adding new admins when SSO is enforced
When SSO is enforced:
- Create the admin in Xink using their email address
- The email must match their Entra ID account
- The admin will automatically be linked on first login
- They can only sign in using Microsoft (SSO)
Xink matches the email address between Entra ID and Xink to automatically complete the connection.
