Applies To
- Pinnacle Series Administrators
- IT Administrators responsible for identity and access management
- Organizations configuring Single Sign-On for Pinnacle Series
Overview
Pinnacle Series supports Single Sign-On (SSO), allowing users to authenticate using their organization’s existing identity provider rather than maintaining a separate set of Pinnacle Series credentials.
SSO can simplify the sign-in experience, improve consistency across applications, and help organizations apply their existing identity and access-management policies to Pinnacle Series.
This guide explains how to configure authentication settings in Pinnacle Series and provides detailed setup instructions for supported SSO configurations.
Use This Guide When
Use this guide if you need to:
- Configure Single Sign-On for your Pinnacle Series tenant.
- Connect Pinnacle Series to Microsoft Entra ID or Okta.
- Configure SSO using SAML or OpenID.
- Determine which users or groups should be permitted to use SSO.
- Configure or review Pinnacle Series password authentication settings.
- Configure Exchange Web Services authentication where applicable.
- Review the prerequisites and permissions required before beginning an SSO implementation.
Before You Begin
Before configuring SSO, ensure that you have:
- Administrative access to your organization’s identity provider.
- Pinnacle Series administrator permissions.
- A stable network connection while completing the configuration.
- The appropriate permissions within Microsoft Entra ID, Okta, or your chosen identity provider.
For Microsoft Entra ID configurations, the guide identifies supported administrative roles such as Global Administrator, Cloud Application Administrator, Application Administrator, or service-principal ownership.
Supported Authentication Options
The guide provides configuration guidance for:
SAML
Configure federated Single Sign-On between Pinnacle Series and an identity provider such as Microsoft Entra ID or Okta.
OpenID
Configure OpenID-based authentication using the identity-provider URLs, Client ID, Signing Key URL, and related application settings required by Pinnacle Series.
Password Authentication
Administrators can manage Pinnacle Series password requirements, including password complexity, expiration, historical password matching, and whether users can reset forgotten passwords themselves.
Exchange Web Services
Exchange Web Services authentication is also documented for applicable Microsoft Exchange environments. The guide notes limitations around multifactor authentication for this method.
Configuration Process
The exact steps depend on your identity provider and authentication method, but the general process is:
- Review the prerequisite requirements and decide which authentication method you will use.
- Create or configure the Pinnacle Series application in your identity provider.
- In Pinnacle Series, go to Admin > Security & Authentication.
- Select the appropriate authentication method and choose Configure.
- Exchange the required URLs, identifiers, certificates, or application credentials between Pinnacle Series and your identity provider.
- Configure which users or groups are permitted to access Pinnacle Series through SSO.
- Save the configuration.
- Test authentication before rolling the configuration out more broadly.
For Microsoft Entra ID SAML, for example, the guide walks through creating the Enterprise Application, configuring user assignment, setting the Identifier and Reply URL, downloading the certificate, entering the Login URL and other values into Pinnacle Series, and then testing the completed configuration.
Important Considerations
When configuring SSO:
- Ensure the email address or user identifier returned by your identity provider matches the corresponding Pinnacle Series user account.
- Decide whether access should be available to all eligible users or restricted to explicitly assigned users or groups.
- Test the configuration with a small number of users before wider deployment.
- Do not remove an existing working authentication method until the new SSO configuration has been successfully tested.
- Record the configuration values used in both Pinnacle Series and your identity provider for future troubleshooting.
Detailed Setup Instructions
For complete step-by-step configuration instructions, including screenshots and provider-specific examples, refer to the attached:
Security and Authentication – Pinnacle Series Single Sign-On and Password Settings Guide
The guide includes:
- Microsoft Entra ID SSO benefits and prerequisites
- Password Authentication settings
- Microsoft Entra ID SAML configuration
- Microsoft Entra ID user assignment
- Okta SAML configuration
- OpenID configuration
- Okta OpenID configuration
- Exchange Web Services configuration
- Authentication testing and troubleshooting guidance
Need Help?
If authentication fails after configuration, verify that all URLs, identifiers, certificates, client IDs, and user attributes match between Pinnacle Series and your identity provider.
If the configuration values appear correct but authentication continues to fail, raise a support ticket and include the authentication method being configured, identity provider, error message received, and any relevant screenshots.
Still Need Help?