Single Sign-On

Secure access with single
sign-on built for your team.

Let your team sign in through your own identity provider, enforce your security policies, and manage access to The Mortgage Office from one place.

A person sits outside using a laptop, smiling with earphones in. An overlay shows a secure access icon labeled “Single Sign-On Authentication.”.

SEE THE DIFFERENCE

Simplify access to TMO.

Managing a separate username and password for every user no longer slows your team down. With TMO, your users sign in through your existing identity provider, and you control access, authentication, and security policy from one place. 

  • Sign in through your existing identity provider 
  • Enforce SSO and multi-factor authentication on your terms 
  • Manage access without juggling separate passwords 

Enterprise-grade access, configured your way.

One identity stack,
end-to-end control.

Bring TMO into your identity stack with secure, centralized sign-in that you control end to end. 

  • Connect any SAML-based identity provider, including Microsoft Entra ID and Okta 
  • Centralize credentials and multi-factor verification with your provider 
  • Configure in minutes with your entity ID and metadata URL 
  • Sign in from the TMO login page or directly from your provider’s dashboard 
  • Match users by email and scope database access automatically 
A user interface screen showing the "Configure SSO" tab under Account Management, with fields for Entity ID and Metadata URL, and Save and Cancel buttons.

HOW IT WORKS

A purple, rounded square icon with a curved line connecting two dots at opposite corners on a light purple background.

Step 1

Configure your identity provider

Enter your entity ID and metadata URL in the Configure SSO section to connect TMO to your identity provider. 

A light blue and teal checkmark icon inside a rounded square border.

Step 2

Enable SSO for your databases

Choose which databases use single sign-on so your team authenticates through your identity provider. 

Simple orange outline icon of an open laptop with a dot above the screen center, displayed on a white background.

Step 3

Sign in through your provider 

Users authenticate through your identity provider from the TMO login page or directly from their provider dashboard.

Simple blue and white shield icon outlined in blue, centered on a light blue rounded square background.

Step 4

Control access and security 

Authentication and multi-factor verification stay with your provider while you manage who can access each database. 

Woman working on laptop at a desk with a login form overlay.

SECURITY & COMPLIANCE

Authenticate on your terms.

Bring TMO into your existing security framework with centralized authentication, enforced sign-in policies, and multi-factor authentication handled by your identity provider. 

  • Centralize authentication through your trusted identity provider
  • Enforce SSO and route multi-factor authentication to support a zero-trust posture 
  • Control database-level access with clear, enforceable sign-in policies 

Partnerships & Integrations

Connect TMO’s SSO capabilites with your team’s existing identity providers and tools to keep access consistent, reduce manual administration, and strengthen security as you scale.

A black square with no discernible features or objects.
Logo with the words "Jonah Direct" in black and blue text, with a stylized "o" in "Jonah" featuring a downward arrow design.
Savvior Logo
Black and yellow logo with a stylized "u" and dot, next to the text "upGrad.
Logo with a stylized lightning bolt inside a circle to the left of the text "LIGHTNING DOCS" in bold, modern font.
The word "xactus" in bold purple lowercase letters, followed by two overlapping stylized "X" shapes in lighter purple shades.
The Cotality logo features the word "cotality" in lowercase letters, with a stylized "C" formed by a pattern of small black triangles.
Filogix logo with purple gradient icon and black text reading "Filogix, a Finastra company" on a light background.

TRUST IN TMO

Built for accuracy, proven at scale.

From individual users to enterprise teams, SSO in TMO keeps access secure, authentication seamless, and your IT team in control without adding friction for the people doing the work

Security is number one. I have to have security. I have to have 100% accuracy. Um anything less than that is just not an option. That’s one of the main reasons why I like The Mo…
Jack Suddarth
Equity Wave Lending
“Initially we considered another tax platform, but when TMO released internal tax tracking it was a no-brainer. I didn’t have to manage a massive spreadsheet for our 170 loa…
Joe Brunello
Managing Director LoanEdge

What is single sign-on in mortgage servicing software? 

Single sign-on (SSO) is an authentication method that lets mortgage servicing staff log in once through a central identity provider and access all connected applications, such as the core servicing platform, document management, and reporting tools, without re-entering credentials. The identity provider (IdP) verifies the user’s identity and issues a secure token that each connected application trusts. In The Mortgage Office, SSO connects directly to your existing IdP so your team authenticates through the same system your organization already controls.

How does single sign-on work with The Mortgage Office?

The Mortgage Office uses SAML-based SSO, meaning you connect your identity provider by entering your entity ID and metadata URL in the Configure SSO section, then enable SSO for each database you want to protect. Once configured, users authenticate through your IdP, either from the TMO login page or directly from your provider’s dashboard, and TMO matches them by email address to grant the correct database access. Authentication and multi-factor verification remain entirely within your identity provider, so your existing security policies apply without any changes to how TMO handles credentials. 

Which identity providers are compatible with The Mortgage Office SSO?

The Mortgage Office supports any SAML-based identity provider, with Microsoft Entra ID (formerly Azure AD) and Okta explicitly supported out of the box. This means mortgage servicers can bring TMO into their existing identity stack without replacing or reconfiguring their current IdP.

What information do I need to set up SSO for The Mortgage Office?

To connect The Mortgage Office to your identity provider, you need two pieces of information from your IdP: your entity ID and your metadata URL. You enter both in the Configure SSO section of TMO, which establishes the trust relationship between your IdP and the platform. Once that connection is in place, you can enable SSO on a per-database basis and map users by their email address to control which databases each person can access.

Can I enable SSO for some databases but not others in The Mortgage Office?

Yes, TMO lets you configure SSO at the individual database level, so you can require identity provider authentication for some databases while leaving others on standard login. This per-database control is useful for organizations that are rolling out SSO in phases or that have different security requirements across portfolios or business units. Each database can be independently scoped, giving administrators precise control over which users authenticate through the IdP and which do not.

How does single sign-on differ from multi-factor authentication?

Single sign-on and multi-factor authentication (MFA) solve different problems: SSO centralizes access so users authenticate once to reach multiple applications, while MFA strengthens that authentication by requiring a second verification factor such as an app push or one-time code. In The Mortgage Office’s SSO model, MFA is enforced at the identity provider level, meaning one MFA challenge at login covers all SSO-protected databases without requiring separate MFA configurations per application. This approach lets mortgage servicers enforce a zero-trust security posture through their existing IdP without adding friction inside TMO itself.

Is SSO more secure than separate usernames and passwords for each application?

SSO is more secure than managing separate credentials per application because it eliminates password reuse across systems, centralizes enforcement of password policies and lockout rules, and makes deprovisioning immediate, disabling one IdP account cuts off access to all connected applications at once. Separate per-application passwords create orphaned accounts and inconsistent policy enforcement, both of which are common audit findings in regulated mortgage servicing environments. When paired with MFA at the identity provider, SSO supports a zero-trust posture that is significantly stronger than distributed credential management.

What happens to a user’s access when they leave the organization or change roles?

When an employee leaves, disabling their account in the identity provider immediately revokes access to every application connected through SSO, including all TMO databases, no manual cleanup is required in each system. Role changes are handled the same way: updating the user’s groups or attributes in the IdP propagates the change to TMO through the SSO session, eliminating orphaned accounts and reducing the risk of over-privileged access. This centralized deprovisioning model directly addresses a common compliance gap in mortgage servicing environments where staff turnover is frequent.

How does The Mortgage Office handle access control across multiple databases with SSO?

The Mortgage Office maps each authenticated user to specific databases by matching their identity provider email to the corresponding user record in TMO, then applies the database-level access permissions already configured for that user. This means SSO handles authentication while TMO retains control over authorization, who can access which database and with what permissions, keeping the two concerns cleanly separated. Administrators manage database access assignments inside TMO and manage authentication policy inside their IdP, with no overlap or conflict between the two systems.

What is the best way to roll out SSO to a mortgage servicing team without disrupting daily operations?

The most effective rollout approach is to enable SSO on a per-database basis in The Mortgage Office, starting with a pilot group, before enforcing it organization-wide. This lets you validate email matching, IdP configuration, and MFA behavior without affecting all users at once. Before go-live, confirm that every user’s email address in TMO matches the identity attribute their IdP will send, and communicate clearly which login flow users should expect so they are not confused by the redirect to the IdP. Keeping direct-login access available during the transition period gives administrators a fallback while SSO is being validated across all databases.

Explore related knowledge

Access a wealth of resources to deepen your understanding of the lending industry. Our Knowledge Hub offers insights, tips, and best practices to help you navigate loan origination and servicing effectively.