Contents:
SENET now supports Single Sign-On (SSO) for both the Central Admin Panel (CAP) and Shell interfaces.
This integration enables your organization to connect SENET to your existing identity provider (Microsoft Entra ID (formerly Azure AD), enabling secure and seamless login for your team members.
Why use SSO
🔐 Stronger security — users only need their corporate credentials, reducing the number of passwords they must remember and lowering the risk of compromised accounts.
⚙️ Simplified access management — manage permissions centrally through your identity provider.
🧠 Better user experience — users need only one corporate account to access all SENET modules they are authorized to use.
📈 Improved compliance and transparency — maintain consistent authentication policies across your organization.
How it works
SENET integrates with your organization’s identity provider Microsoft Entra ID (Azure AD) using a secure OpenID Connect (OIDC) connection.
Once configured, users can log in to SENET using their corporate credentials, eliminating the need for separate SENET passwords.
How to set up SSO
If your organization uses Microsoft Azure AD, follow the steps below to register SENET in your Azure environment. Our support team will then finalize the setup on the SENET side.
Step 1. Register SENET in your Azure AD
Sign in to your organization’s Azure Portal.
Navigate to Microsoft Entra ID → App registrations → New registration.
-
Fill in:
Name: e.g.,
SENET SSO IntegrationSupported account types: Accounts in this organizational directory only (Single tenant)
Redirect URI (Web):
Use this link
https://keycloakx.enes.tech/realms/<orgname>/broker/microsoft/endpoint
Paste it as is, then replace orgname with the actual name of your organization.
🔎 If you’re not sure what your organization's name is, you can copy it directly from the URL shown in your admin panel.
Here, “integration” is the organization name.
Example link:
Click Register.
Step 2. Сheck authentication
Open your new app in Azure Portal.
Go to Authentication.
Make sure the Redirect URI is correct (no spaces, no trailing slashes).
Save the changes.
Step 3. Generate a Client Secret
Open Certificates & secrets → Client secrets.
Click New client secret.
Add a description (for example, SENET Integration) and set an expiration period.
Click Add, then copy the Value immediately — it’s shown only once.
Step 4. Share credentials with SENET
Send the following details to the SENET support team via a secure communication channel:
Application (Client) ID
Tenant ID
Client Secret (Value)
The team will complete the configuration on our side and confirm when SSO is ready for use.
Step 5. Test the connection
Go to your SENET login page.
Click Sign in with Microsoft.
Enter your corporate credentials.
If the login is successful, your SSO integration is working correctly.
First-time login and account linking
When your organization uses an external identity provider (Microsoft Entra ID), SENET does not create separate passwords or local accounts.
When a user logs in via SSO for the first time, SENET automatically creates a profile in its system using the existing corporate credentials.
The email field is automatically filled in based on your organization’s corporate domain.
Once the profile is created, the user can sign in to SENET through SSO.
If the user’s SENET profile is incomplete, they are redirected to the Complete Registration page.
Access to Shell will be granted only after all required fields are filled in.
📌 Users must exist in the organization’s identity provider (Microsoft Entra ID / Azure AD or Google Workspace) before they can log in via SSO. If a user does not exist in the identity provider, SENET cannot create a profile automatically.
Changes in Shell and CAP behavior
Shell login
Only SSO login is available.
Local login methods such as username/password or login by receipt are hidden.
Password reset and profile editing are disabled — credentials are managed through your corporate identity provider.
CAP login
For organizations using an external database, the Reset password option is removed.
In CAP, the Status column shows the account state. Pending means the user has not completed registration or verification.
Security and access confirmation
Actions that previously required entering a password (cash in/out, return receipt, close shift, Z-report) now use a confirmation page, eliminating the need to enter a password.
All authentication and access control are handled through your corporate identity provider, ensuring centralized and secure login.
Need help?
If your users experience login issues, or if your Azure credentials (Client Secret or Tenant ID) change, please contact SENET technical support. Our team will review the integration and update the configuration as needed.
Comments
0 comments
Please sign in to leave a comment.