Advarra Single Sign-On (SSO) is an authentication method that provides a more streamlined experience, allowing you to use one set of credentials to log in to multiple applications, when those applications and environments are configured to use Advarra SSO.
Getting Started with Advarra SSO
After the necessary setup is complete and Advarra SSO is enabled for an application environment or individual users, users are sent an email invitation to create an SSO account. Click the link in the email and complete the steps described below to set up your account. As part of this setup, if your organization isn't using its own identity provider (IdP) and is instead using the Advarra IdP, you're prompted to create a password and set up multi-factor authentication (MFA). If your organization is using its own IdP, you are not prompted to create a password or set up MFA; you can use your existing organization password, and your MFA options are determined by your organization's IdP, not Advarra.
After you log in via Advarra SSO, you are directed to the Advarra One homepage. We recommend bookmarking the homepage so you can access it at any time. More information about navigating Advarra One is included in the steps below.
Additionally, we recommend that your email address in SSO-enabled applications/instances is formatted in a single case (such as john.doe@advarra.com instead of John.Doe@Advarra.com) before an administrator invites you to avoid potential errors related to mixed-case emails.
Setup
Complete these steps to set up your SSO account and begin using Advarra One.
- Open the email invitation you were sent to create your Advarra SSO account. SSO-related emails come from the no-reply@advarracloud.com email address.
- Click the link in the email. If the link is expired, follow the prompts to generate a new link.
-
The Account Registration page opens. Enter your first and last name, confirm your email address, and create your password if prompted.
If your organization has its own IdP, you aren't prompted to create a password; you can use your existing organization password.
You must also scroll through and read the Terms and Conditions and click the Accept and Create Account button to continue.
- The Advarra One login page opens. Enter your email address and click Next.
-
If your organization is using its own IdP, you’re redirected to your organization’s page to finish logging in.
If you’re using the Advarra IdP, enter your password and click Log In. When entering your password, if you notice a mistake in your email address, click the "Log in as a different user" link below the Log In button to return to the login page and re-enter your email address.
- If you're using the Advarra IdP, the Multi-Factor Authentication page opens. Click the "Add multi-factor method" button to set up a multi-factor authentication method. If you're using your organization's IdP, you aren't prompted to do this; your authentication options are determined by your organization's IdP, not Advarra. Your setup is complete and you can skip to the Navigation section below.
- The Enable Multi-Factor page opens. Select the authentication method to use: an authenticator app or email. Note that if you choose to use an authenticator app, you will need to use a smartphone or similar device to access that app each time you log in with Advarra SSO. If you use email, you will need to access your email account each time you log in with Advarra SSO. Advarra recommends using an authenticator app, as that's the most secure method.
- Use the method you selected to retrieve a verification code.
- If you chose to use an authenticator app:
- Download and/or open your authenticator app and follow the app's instructions to add an account. (See the Additional Notes and Troubleshooting section below for links to instructions for a few commonly used apps.)
- When prompted by the app, either scan the QR code or enter the encoded secret provided on the Enable Multi-Factor page.
- On the Enable Multi-Factor page, enter the code from your authenticator app in the Verification code field and click Enable.
- Note that you can use any authenticator app, including Google Authenticator, Microsoft Authenticator, Authy, and Okta. You can also use a password manager such as 1Password as your authenticator app, to minimize the number of apps you need to manage.
- If you chose to use an authenticator app:
- If you chose to use email:
- In the Email field, enter the email address where you would like to receive a verification code. You can use any email address you'd like; it doesn't need to be the same as the email address you're using to log in.
- Click "Send a one-time code."
- Go to your email and open the email message with a subject of "Your multi-factor authentication code" from no-reply@advarracloud.com. It might take a few minutes for the code to be sent.
- On the Enable Multi-Factor page, enter the code from the email message in the Verification code field and click Enable.
- A message appears indicating that multi-factor authentication has been enabled. Click Done.
- You're returned to the Multi-Factor Authentication page, which now lists the authentication method you added. You can add another authentication method or click the Go to Advarra One Homepage link to continue.
- The Multi-Factor Authentication page opens and prompts you for a code. If you have more than one authentication method set up, you are first prompted to select the method you want to use.
- Go to your authenticator app or email to retrieve the code. It might take a few minutes for the code to be sent.
- On the Multi-Factor Authentication page, enter the code. You can also select the "Trust this device" checkbox to prevent the authentication challenge from appearing for a limited time.
- Note that if you didn't receive the code or if you are having trouble with the code, you can click the "Request a new verification code" link. This link is available after the code is initially sent. Alternatively, if you have more than one authentication method configured, you can click the “Authenticate using a different method” link to view the authentication methods that are set up and select a different method to use.
- Click Verify.
Login
Logging in with Multi-Factor Authentication
If you're using the Advarra IdP, you will be prompted to complete an MFA challenge when you log in, after you enter your password.
If you're using your organization's IdP, you aren't prompted to do this; your authentication options are determined by your organization's IdP, not Advarra.
To log in with MFA, complete the following steps:
- On the login page, enter your email and password and click Log In.
- The Multi-Factor Authentication page opens and prompts you for a code. If you have more than one authentication method set up, you might first be prompted to select the one you want to use. Otherwise, the authentication challenge uses the most recently used authentication method.
- Go to the authenticator app or email that you're using for multi-factor authentication to retrieve the code. It might take a few minutes for the code to be sent.
- On the Multi-Factor Authentication page, enter the code. You can also select the "Trust this device" checkbox to prevent the authentication challenge from appearing for a limited time.
- Note that if you didn't receive the code or if you are having trouble with the code, you can click the "Request a new verification code" link. This link is available after the code is initially sent. Alternatively, if you have more than one authentication method configured, you can click the “Authenticate using a different method” link to view the authentication methods that are set up and select a different method to use.
- Click Verify. The Advarra One homepage opens.
Resetting a Forgotten Password
If your organization is using the Advarra IdP, you can reset your password on the login page if you've forgotten it.
If your organization set up a direct login connection to Advarra SSO (your organization is using its own IdP) and you need to reset your password, contact your organization's IT support. Advarra cannot update your password if you use your organization's credentials.
To reset your password, complete the following steps. Note that you must have already set up multi-factor authentication (MFA) in order to reset your password using these instructions.
- On the login page, enter your email and click Next.
- On the page that opens, click the “Forgot your password?” link.
- The Forgot Password page opens. Confirm that the displayed email is correct and click Submit.
- Go to the email you’re using to log in and open the email message with a subject of “Advarra Password Reset” from no-reply@advarracloud.com. Click Reset Password in the email.
- The Confirmation Required page opens and informs you that you must complete an authentication challenge prior to resetting your password. To proceed, click Continue.
- The Multi-Factor Authentication page opens and prompts you for a code. If you have more than one authentication method set up, you might first be prompted to select the one you want to use. Otherwise, the authentication challenge uses the most recently used authentication method.
- Go to the authenticator app or email that you're using for multi-factor authentication to retrieve the code. It might take a few minutes for the code to be sent.
- On the Multi-Factor Authentication page, enter the code. You can also select the "Trust this device" checkbox to prevent the authentication challenge from appearing for a limited time.
- Note that if you didn't receive the code or if you are having trouble with the code, you can click the "Request a new verification code" link. This link is available after the code is initially sent. Alternatively, if you have more than one authentication method configured, you can click the “Authenticate using a different method” link to view the authentication methods that are set up and select a different method to use.
- The Change Password page opens. Enter and confirm your new password. Make sure your password meets the criteria listed below the Confirm Password field.
- Click Update. On the Password Updated page that opens, you can click the “Return to login” link to log in with your new password.
If you were logged in to any Advarra One sessions at the time that you reset your password, you’ll be logged out of them when you create your new password.
The system limits you to a certain number of password resets within a limited period. If you exceed this limit, you're restricted from resetting it for a longer period of time. You can't reset your password using the "Forgot your password?" link if your account is locked; to unlock your account, contact Product Support.
Navigation
After you've set up your account and logged in, the Advarra One homepage opens. From Advarra One, you can navigate to other SSO-enabled applications or instances to which you have access. At the top of the page, you can choose to view production or non-production instances depending on the types of instances to which you have access:
- If you have access to both types, you can click and view instances in either tab.
- If you only have access to non-production instances, both tabs are displayed but you can only view non-production instances.
- If you only have access to production instances, the tabs aren't displayed and you can only view production instances.
If available, production instances are displayed by default. Tiles appear for SSO-enabled application instances that you have access to.
Click the tile for the instance you want to open. If you have access to multiple instances for an application (indicated by a number on the application tile), click to view and select one of those instances. Instances are displayed in alphabetical order. Clicking an instance opens it in a new browser tab.
If you don't have access to any SSO-enabled applications, no tiles are displayed on the homepage.
Updating Account Settings
If your organization is using the Advarra IdP, you have options to change your password and update your multi-factor authentication setup from the Advarra One homepage.
If you're using your organization's IdP, then your password and authentication options aren't managed by Advarra and you must work with your organization to manage them.
Change Password
To change your password, complete the following steps:
- On the Advarra One homepage, go to the user menu > Change Password. To access the user menu, click your name in the upper right corner of the Advarra One homepage.
- The Change Password page opens.
- Confirm your current password, then enter and confirm your new password. Make sure your password meets the listed criteria.
- Click Update.
After you change your password, you will receive an email confirming the change.
Update Multi-Factor Authentication Setup
You can view or update your MFA setup at any time. If you’re using an authenticator application, you might need to update your setup when you want to use a new device. If you’re using email, you might need to update your setup if you change your email.
To view/update your multi-factor authentication setup:
- On the Advarra One homepage, go to the user menu > Multi-Factor Authentication.
- The Multi-Factor Authentication page might appear and prompt you for a code. Follow the same steps to retrieve and enter the code as described in the Logging in with Multi-Factor Authentication section.
- The Multi-Factor Authentication page opens and displays the authentication methods that are currently configured.
- To add a new authentication method, click the "Add multi-factor method" button. Follow the same steps to add a method as described in the Setup section (steps 6-8).
- To remove an authentication method, click the Remove (-) icon for the method. You're prompted to use that authentication method to retrieve a code that you must enter before you can remove it.
- You must have at least one authentication method. This means that if you have only one authentication method, you can't remove it until you have set up another method.
- Note that if you’re removing an email method, you must click the “Send a one-time code” button to be sent the code. If you didn't receive the code or if you are having trouble with the code, you can click the "Request a new verification code" link.
- Click the "Go to Advarra One Homepage" link to return to the homepage.
Additional Notes and Troubleshooting
Note that:
- After you have set up and logged in with Advarra SSO, if SSO is enabled for an additional application instance to which you have access (and for which you're using the same email address), the system will send you a notification email to inform you that you've been granted access to a new instance and the tile for that instance will appear on your Advarra One homepage. No additional setup is needed.
- When your user is made active or inactive in an application, that update is also reflected in Advarra SSO and the tile for the application instance is added or removed as appropriate on the Advarra One homepage. If your account is made active after being inactive, the system will send you a notification email to inform you that you've been granted access.
- When the SSO or application session ends or times out, or you log out of Advarra One (user menu > Log out) or an application, you're logged out of Advarra SSO as well as any applications you logged in to with Advarra SSO and redirected to the Advarra One login page.
- For instructions or more information about using an authenticator app, refer to that product's help content. A few commonly used apps are:
- The Manage PIN option available from the Advarra One page (user menu > Manage PIN) is currently not in use.
- If the Terms and Conditions are updated, the next time you log in to Advarra SSO you will be prompted to review and accept them again. You can click the Terms and Conditions link in the footer of the Advarra One homepage to review them at any time. The Terms and Conditions are the same across Advarra.
- If an error occurs or a page doesn't load as expected, try refreshing the page or re-triggering your action, as this might resolve the issue.
- If you see a "This site can't be reached" message when attempting to log in, your organization's technical team might need to ensure that your organization's firewall and security policies allow users to browse to the following domains:
- advarracloud.com
- advarracloud.au
- advarracloud.eu
- clinicalconductor.com
- cctrialsuite.com
- longboat.com
- forteresearchapps.com
- advarra.app
Contact Product Support to:
- Update the email address for a user authenticating with SSO.
- Update the first or last name for a user in Advarra SSO.
- Deactivate an Advarra SSO user.
Additional Resources
-
SSO Help Center (linked on the Advarra One login page)
Provides assistance during login, including answers to common login questions and issues and information about who to contact for additional support.