---
title: How to Enforce Users to Only Use Single Sign-On (SSO) Microsoft Entra ID as a Login Method
slug: portal-sub/how-to-enforce-users-to-only-use-single-sign-on-sso-microsoft-entra-id-as-a-login-method
docTags: 
createdAt: 2026-03-04T12:03:15.534Z
---

# Overview & Requirements

The following article is intended for System Administrators or technical users of Profile.
It will explain how to force the Profile user to only be able to log in with Single Sign-On (SSO) with Microsoft Entra ID and prevent them from using the traditional Profile login method.

## Requirements

- Profile version 10.0.5 or later
- Microsoft Entra ID for your organization's Identity Management
- SSO Microsoft Entra ID license for Profile
- Configuration processes have been completed

# Enforcing Users to Only Use SSO Microsoft Entra ID as a Login Method

::::WorkflowBlock
:::WorkflowBlockItem
Ensure the user has a local account in Profile.
:::

:::WorkflowBlockItem
Go to **Organisation / People and Places**.

1. Select the appropriate user.
2. Go to **Special**.
3. Ensure the user's Settings has **SSO Username** checkbox is selected.
4. Ensure the user's corresponding Microsoft Entra ID email account is entered into the **SSO Username** field.
:::

:::WorkflowBlockItem
Change their Profile user password and do not share the new password with the user. This ensures the user cannot login with the local Profile account.
:::

:::WorkflowBlockItem
As a result, the user can only log in using Microsoft Entra ID.
:::

:::WorkflowBlockItem
Ensure you disable the ability for users to click **I forgot my password** on the traditional Profile Login screen by navigating to: **Preferences / Technical / Security (Global) / Security &#xA0;**&#x74;ab and uncheck **Show "I forgot my password" link**.
:::
::::

:::hint{type="info"}
**Note:&#x20;**&#x54;his will prevent them from being able to reset their local Profile password and logging into Profile through the traditional authentication method. Please note that if you proceed with this, any existing processes within Profile that still require their local Profile password (eg. merging patient charts) will be impacted, as users will not know their new password after resetting and will be unable to perform those workflows.

:::

# Learn More

For more information on Microsoft Entra ID in Profileplease click on the article links below:

- [Microsoft Entra ID in Profile](docId:7vBBYDxhIcV4CIg1vbcWD)
- [Microsoft Entra ID in Profile: FAQ](docId\:BcQmJgnOCa-MMuINnxwJQ)
- [How to Configure the Profile Application in Microsoft Entra ID Tenant](docId\:ahJpd7hIPDMpNmyKgkhD7)
- [How to Add Single Sign-On MS Entra ID License in Profile](docId\:wiKAAADVi80fASeTQMUKv)
- [How to Configure Single Sign-On (SSO) for Microsoft Entra ID in Profile](docId:1zwBi7NJEDkcJkBfMnPyZ)
- [How to Configure Existing Users for Single Sign-On (SSO) with Microsoft Entra ID in Profile](docId\:Dx0Y5TYBX-QkQ2ROhI0z-)
- [How to Add new Users to Profile for Single Sign-On (SSO) with Microsoft Entra ID in Profile](docId\:InFKWTP01GtHumhdrkB2n)
- [How to Prevent Users from Using Microsoft Entra ID Single Sign-On (SSO) as a Login Method](docId\:Z9BjONEx05g1ui4JOlQBK)
