Federated Access and Sign-In: Self-Service Authentication Setup
Solution Overview
Federated sign‑in connects your organization’s identity provider to Surescripts, allowing users to sign in to Workbench, the Specialty Medications Gateway, and the Prior Authorization Portal using their existing corporate credentials.
After federation is configured, users no longer manage a separate Workbench username, password, or multi‑factor authentication. Instead, users authenticate through your organization’s identity provider when accessing Surescripts applications. Depending on your organization’s configuration, users may be redirected automatically to the identity provider or prompted to sign in using their corporate credentials.
Once you’ve validated that federated access works for all users, you can require federated sign‑in and disable username‑and‑password authentication.
This guide is written for Identity and Access Management administrators completing a self‑service setup of federated sign‑in. It covers the prerequisites you’ll gather from your identity provider, the configuration required in Workbench, and how to validate the integration before requiring federated sign‑in for all users.
What You Get
With federated sign‑in, your organization benefits immediately with the following:
- A simpler sign-in experience for Workbench users — Users sign in with their existing corporate credentials and your organization’s multi‑factor authentication, with no separate Surescripts login.
- A stronger security model — Authentication, conditional access, and offboarding policies are enforced by your identity provider and apply consistently to Surescripts access.
- Streamlined access enablement — Federated sign‑in replaces password‑based access while existing user account creation and access role processes remain unchanged.