Gate Content with SSO
Restrict a microsite or content hub to authenticated employees using SSO, so only people who sign in with your corporate identity provider can view it.
Scenario
You are publishing sensitive material — an internal announcement, a benefits hub, a policy microsite — and you want it visible only to current employees, not to anyone who happens to receive or forward the link. By putting the content behind SSO, each visitor must authenticate against your identity provider (typically Microsoft Entra ID) before the page renders. This keeps distribution effortless while ensuring the audience is who you expect.
Prerequisites
- An identity provider configured for SSO (for example, Microsoft Entra ID). Your admin usually sets this up once at the account level.
- A microsite or content hub already built and ready to publish.
- Agreement on which groups or domains are allowed in — confirm with whoever owns your identity provider.
- Admin rights to enable access restrictions on a microsite (confirm the exact steps in your account).
Steps
- Build the microsite that will hold the gated content. See Microsites & experiences.
- In the microsite's access or security settings, turn on the option to require authentication and select SSO as the method (confirm the exact steps in your account).
- Scope access to the right audience — an allowed domain, an Entra ID group, or a defined list — so only intended employees pass the gate.
- Publish, then test the link yourself in a private browser window: you should be redirected to sign in, and reach the content only after authenticating.
- Distribute the link in a Broadcast. Recipients who click are prompted to sign in before the page loads.
Measure success
- Confirm every visit is authenticated: unauthenticated attempts should be blocked or redirected, never shown the content.
- Watch engagement on the Broadcast that carried the link, and compare click volume to actual authenticated page views to spot forwarded-but-blocked traffic. See the Metrics dictionary.
- Periodically re-check that your allowed groups still match your intended audience as people join or leave.
Related
Canonical terms: Author, Edition, Folder (Project Folder), Broadcast. See the Glossary.