Security is number one. I have to have security. I have to have 100% accuracy. Um anything less than that is just not an option. That’s one of the main reasons why I like The Mo…
Single Sign-On
Secure access with single
sign-on built for your team.
Let your team sign in through your own identity provider, enforce your security policies, and manage access to The Mortgage Office from one place.
JUMP TO:
SEE THE DIFFERENCE
Simplify access to TMO.
Managing a separate username and password for every user no longer slows your team down. With TMO, your users sign in through your existing identity provider, and you control access, authentication, and security policy from one place.
- Sign in through your existing identity provider
- Enforce SSO and multi-factor authentication on your terms
- Manage access without juggling separate passwords
Solutions & cAPABILITIES
Enterprise-grade access, configured your way.
One identity stack,
end-to-end control.
Bring TMO into your identity stack with secure, centralized sign-in that you control end to end.
- Connect any SAML-based identity provider, including Microsoft Entra ID and Okta
- Centralize credentials and multi-factor verification with your provider
- Configure in minutes with your entity ID and metadata URL
- Sign in from the TMO login page or directly from your provider’s dashboard
- Match users by email and scope database access automatically
HOW IT WORKS
Secure access, simplified.
Step 1
Configure your identity provider
Enter your entity ID and metadata URL in the Configure SSO section to connect TMO to your identity provider.
Step 2
Enable SSO for your databases
Choose which databases use single sign-on so your team authenticates through your identity provider.
Step 3
Sign in through your provider
Users authenticate through your identity provider from the TMO login page or directly from their provider dashboard.
Step 4
Control access and security
Authentication and multi-factor verification stay with your provider while you manage who can access each database.
See single sign-on in action.
SECURITY & COMPLIANCE
Authenticate on your terms.
Bring TMO into your existing security framework with centralized authentication, enforced sign-in policies, and multi-factor authentication handled by your identity provider.
- Centralize authentication through your trusted identity provider
- Enforce SSO and route multi-factor authentication to support a zero-trust posture
- Control database-level access with clear, enforceable sign-in policies
Partnerships & Integrations
Connect TMO’s SSO capabilites with your team’s existing identity providers and tools to keep access consistent, reduce manual administration, and strengthen security as you scale.
FAQs
What is single sign-on in mortgage servicing software?
Single sign-on (SSO) is an authentication method that lets mortgage servicing staff log in once through a central identity provider and access all connected applications, such as the core servicing platform, document management, and reporting tools, without re-entering credentials. The identity provider (IdP) verifies the user’s identity and issues a secure token that each connected application trusts. In The Mortgage Office, SSO connects directly to your existing IdP so your team authenticates through the same system your organization already controls.
How does single sign-on work with The Mortgage Office?
The Mortgage Office uses SAML-based SSO, meaning you connect your identity provider by entering your entity ID and metadata URL in the Configure SSO section, then enable SSO for each database you want to protect. Once configured, users authenticate through your IdP, either from the TMO login page or directly from your provider’s dashboard, and TMO matches them by email address to grant the correct database access. Authentication and multi-factor verification remain entirely within your identity provider, so your existing security policies apply without any changes to how TMO handles credentials.
Which identity providers are compatible with The Mortgage Office SSO?
The Mortgage Office supports any SAML-based identity provider, with Microsoft Entra ID (formerly Azure AD) and Okta explicitly supported out of the box. This means mortgage servicers can bring TMO into their existing identity stack without replacing or reconfiguring their current IdP.
What information do I need to set up SSO for The Mortgage Office?
To connect The Mortgage Office to your identity provider, you need two pieces of information from your IdP: your entity ID and your metadata URL. You enter both in the Configure SSO section of TMO, which establishes the trust relationship between your IdP and the platform. Once that connection is in place, you can enable SSO on a per-database basis and map users by their email address to control which databases each person can access.
Can I enable SSO for some databases but not others in The Mortgage Office?
Yes, TMO lets you configure SSO at the individual database level, so you can require identity provider authentication for some databases while leaving others on standard login. This per-database control is useful for organizations that are rolling out SSO in phases or that have different security requirements across portfolios or business units. Each database can be independently scoped, giving administrators precise control over which users authenticate through the IdP and which do not.
How does single sign-on differ from multi-factor authentication?
Single sign-on and multi-factor authentication (MFA) solve different problems: SSO centralizes access so users authenticate once to reach multiple applications, while MFA strengthens that authentication by requiring a second verification factor such as an app push or one-time code. In The Mortgage Office’s SSO model, MFA is enforced at the identity provider level, meaning one MFA challenge at login covers all SSO-protected databases without requiring separate MFA configurations per application. This approach lets mortgage servicers enforce a zero-trust security posture through their existing IdP without adding friction inside TMO itself.
Is SSO more secure than separate usernames and passwords for each application?
SSO is more secure than managing separate credentials per application because it eliminates password reuse across systems, centralizes enforcement of password policies and lockout rules, and makes deprovisioning immediate, disabling one IdP account cuts off access to all connected applications at once. Separate per-application passwords create orphaned accounts and inconsistent policy enforcement, both of which are common audit findings in regulated mortgage servicing environments. When paired with MFA at the identity provider, SSO supports a zero-trust posture that is significantly stronger than distributed credential management.
What happens to a user’s access when they leave the organization or change roles?
When an employee leaves, disabling their account in the identity provider immediately revokes access to every application connected through SSO, including all TMO databases, no manual cleanup is required in each system. Role changes are handled the same way: updating the user’s groups or attributes in the IdP propagates the change to TMO through the SSO session, eliminating orphaned accounts and reducing the risk of over-privileged access. This centralized deprovisioning model directly addresses a common compliance gap in mortgage servicing environments where staff turnover is frequent.
How does The Mortgage Office handle access control across multiple databases with SSO?
The Mortgage Office maps each authenticated user to specific databases by matching their identity provider email to the corresponding user record in TMO, then applies the database-level access permissions already configured for that user. This means SSO handles authentication while TMO retains control over authorization, who can access which database and with what permissions, keeping the two concerns cleanly separated. Administrators manage database access assignments inside TMO and manage authentication policy inside their IdP, with no overlap or conflict between the two systems.
What is the best way to roll out SSO to a mortgage servicing team without disrupting daily operations?
The most effective rollout approach is to enable SSO on a per-database basis in The Mortgage Office, starting with a pilot group, before enforcing it organization-wide. This lets you validate email matching, IdP configuration, and MFA behavior without affecting all users at once. Before go-live, confirm that every user’s email address in TMO matches the identity attribute their IdP will send, and communicate clearly which login flow users should expect so they are not confused by the redirect to the IdP. Keeping direct-login access available during the transition period gives administrators a fallback while SSO is being validated across all databases.
Explore related knowledge
Access a wealth of resources to deepen your understanding of the lending industry. Our Knowledge Hub offers insights, tips, and best practices to help you navigate loan origination and servicing effectively.
Manual vs. Automated Loan Servicing: What Lenders Need to Know
The modern loan servicing landscape is complex.
Renovo’s CEO Kevin Werner Shares His Perspective on Scaling Loan Operations
In this short 3-minute video, Kevin Werner, CEO of Renovo Financial, shares insights from
7 Ways to Modernize Your Loan Programs: The TMO Playbook
Learn the strategies already trusted by more than 25 counties and a growing number of hous
Ready to power your business with The Mortgage Office?
Let us show you how efficient and accurate your loan management platform can be.