Hello, I’m Nora, your AI guide from Technology Last Stop. This guide covers Company and TLS single sign-on. Configure Microsoft, Google, Okta, OneLogin or SAML with immutable identity links and mandatory MFA. Current availability: Implemented; verification required. Before you start. An authorized administrator with mandatory MFA completed. The correct company and provider permissions; keep credentials out of screenshots and chat. Step 1. TLS owners open /admin/identity for staff SSO. Company administrators open their company > Identity & SSO. Confirm the company ID and whether the connection is for platform staff or a customer. Step 2. Create a web OIDC application in the correct provider. Microsoft uses its tenant UUID; Google uses the approved Workspace domain and web client; Okta and OneLogin use the validated organization issuer. Register the callback shown in the portal. Step 3. Enter the client ID and protected client secret. Use only the supported provider issuer. Save and enable the connection. Configuration saved does not prove a real sign-in. Step 4. Link each approved portal account to the provider immutable subject. Microsoft uses the tenant/object identity; Google, Okta and OneLogin use their immutable subject. Matching email or a public domain alone grants no access. Step 5. For TLS SSO, open Company SSO at /login and enter tls or techlaststop.com. For a customer, enter its company ID or registered domain and choose its provider. Step 6. Complete a real authorized demo sign-in and LastStop Verify/MFA. Test a wrong company, an unlinked subject, a suspended user and a revoked connection. Step 7. Rotate credentials and review the resulting provider revision. Existing federated sessions must reauthenticate after configuration changes. Preserve an approved recovery path without disabling MFA. Now verify the result. Provider verified state follows an actual completed callback. A customer identity cannot become a TLS staff owner. Dev/QA TLS access continues using the production identity authority. If you get stuck. Do not recreate users to fix a provider error; check the immutable link, tenant, issuer and callback. Per-company Dev/QA automatic provisioning and continuous identity mirroring are still separate implementation and acceptance gates. Use the current written guide for exact URLs, permission names, and provider documentation. Pause before entering credentials, and keep them in protected configuration. I’m Nora, your TLS guide.