SSO implementation guide

Prev Next

This guide takes you through enabling Single Sign-On for your Hexagon GeoCloud company account, from preparing the account to migrating your team. Follow it in order — each phase depends on the one before it.

Who this guide is for

  • The GeoCloud administrator in your company, who prepares the account and later migrates the team.

  • The IT or identity colleague in your company, who registers the application in your identity provider and completes the request form.

Read the whole guide before you start. Every step heading names the role that carries it out. Most of phase 2 belongs to IT, so the administrator needs to know what to hand over and when.

What to expect

Single Sign-On is available to Enterprise customers. GeoCloud supports OIDC (OpenID Connect); SAML is not supported. Once your completed request form reaches Hexagon, activation takes approximately two weeks until SSO is ready to test. You will be notified as soon as SSO is live. No action is required from you while you wait.

Note. GeoCloud does not include Multi-Factor Authentication natively. To enforce MFA, configure it in your identity provider, which handles it before authentication is passed to GeoCloud.

Who does what

Role

Responsibility

GeoCloud administrator in your company

Creates or holds the company account, activates the subscription, invites the IT contact as an Admin, and later migrates the team to SSO.

IT or identity contact in your company

Registers the OIDC application in your identity provider and completes the SSO request form with the resulting values.

Hexagon Customer Success

Confirms eligibility, provides the request form, coordinates activation on the Hexagon side, and confirms when SSO is available.

Phase 1 — Prepare the company account

1. Create your GeoCloud company account — GeoCloud administrator in your company

Skip this step if your organisation already has a company account.

Create one at geocloud.hxdr.app by clicking Create company account. This first account uses e-mail and password rather than SSO, and automatically becomes an Admin user.

  • Enter your personal details. Confirm that Voucher applied appears on the left of the screen before continuing.

  • Enter your company details: name, address, phone number and, if applicable, VAT number.

  • Accept the Terms of Use, complete the registration, and follow the Verify email link.

Full procedure: Sign up for a Company Account

2. Activate your subscription — GeoCloud administrator in your company

Log in to geocloud.hxdr.app with the Admin account. Click your account badge in the lower left, click Subscriptions, then click Enter EID. Enter your Entitlement ID and click Submit.

  • The Entitlement ID arrives by e-mail, either in the attached Entitlement Certificate or in the message body alongside a unique activation link.

  • The certificate product must read GeoCloud Subscription. Any other product is the wrong Entitlement ID.

  • After activation, check that the data quota shown matches what you purchased.

Full procedure: Activating your subscription

3. Involve the IT department responsible for SSO — GeoCloud administrator in your company

Identify the colleague in your organisation who handles Single Sign-On requests and administers your identity provider. This person carries out the technical configuration and completes the request form, so involve them before going any further.

4. Give the IT contact an Admin account — GeoCloud administrator in your company

In the Users menu of your company account, invite the IT contact with the Admin role, so they have the user-management rights needed for the setup. If they already have a user, change that user's role to Admin.

Full procedure: Add users to your account

Phase 2 — Configure OIDC and submit the request

5. Choose a company alias — GeoCloud administrator in your company, agreed with your IT contact

The alias identifies your organisation inside the GeoCloud authentication platform and forms part of the redirect URI, so agree on it with IT before the configuration starts. The alias must be:

  • all lowercase;

  • free of special characters;

  • no longer than 23 characters.

6. Register the OIDC application in your identity provider — IT contact in your company

Your IT contact registers GeoCloud as an OIDC application. The values to register, and the Hexagon-specific deviations from the Microsoft procedure, are covered in full on a dedicated page.

Full procedure: How to configure your OIDC SSO

By the end of this step, IT should have the following to hand: the OIDC metadata document URL, the Client ID, the Client Secret Value, and the secret's expiration date.

Warning — handling the client secret. The OIDC metadata document contains no secrets — only the URIs needed for the OIDC flow. The client secret is sensitive: submit it only through the request form, never by plain e-mail or chat. In Microsoft Entra ID, copy the secret Value, which is visible only once, immediately after you create it. Do not copy the Secret ID.

7. Request and complete the SSO request form — IT contact in your company

The request form is not published. Contact your regional Customer Success team to obtain it:

Region

Contact

EMEA

customersuccess.realitycapture.emea@hexagon.com

APJ

customersuccess.realitycapture.apj@hexagon.com

Americas

customersuccess.realitycapture.americas@hexagon.com

Gather all of the values below before you open the form, and check each one before submitting. Incomplete or inconsistent values are the most common cause of delay.

Values to submit on the SSO request form

Field

What to enter

Client organisation name

The name of the organisation to be registered for SSO.

Contact info

The e-mail address of the person handling the SSO registration and integration — typically the IT administrator.

GeoCloud Company Account Administrator

The e-mail address of the Admin user of your company account.

Company alias

The alias from step 5: lowercase, no special characters, maximum 23 characters.

OIDC metadata URL

The metadata endpoint of your identity provider. This usually ends in .well-known/openid-configuration.

Client ID

From your OIDC application registration. This allows GeoCloud to contact your identity provider.

Client Secret Value

The secret Value generated during the OIDC configuration — not the Secret ID.

Client Secret expiration date

Format YYYY/MM/DD. If the secret does not expire, enter Unlimited.

Email domain(s)

Every domain your users sign in with, for example @hexagon.com.

8. Submit the form and await activation — IT contact in your company

Submit the completed form to Hexagon. Activation takes approximately two weeks from submission until SSO is ready to test, and nothing further is required from you in the meantime. You will be notified once SSO is active.

Warning. Do not delete any existing accounts before you receive that confirmation. Plan the phase 3 rollout for afterwards.

Phase 3 — Go live

9. Set up your own SSO admin user — GeoCloud administrator in your company

Once SSO is active, go to hxdr.app, click Single Sign-On, and sign in with your company e-mail address. Your SSO user is created automatically on first login and appears in the Users menu with the role Employee and the title Not Available.

  • Log back in with your non-SSO credentials and change the role of your SSO user to Admin.

  • If your non-SSO user owns any projects, transfer ownership and memberships to your SSO user before deleting it.

  • Log in again through SSO. You now have the full Admin menu, and can delete your legacy non-SSO user.

Full procedures: Set up your SSO admin account · Moving project ownership to SSO user

10. Roll out SSO to the rest of your team — GeoCloud administrator in your company

Work from your SSO admin account. No invitations are needed: colleagues who sign in through SSO with their company e-mail get an account automatically, which you then assign a role and add to projects.

  • Legacy users without projects — delete the legacy accounts, ask the users to sign in through SSO, then assign their roles.

  • Legacy users who own or belong to projects — announce the migration, have each user sign in through SSO and transfer their projects, then confirm back to you. Verify that the SSO account reaches all expected projects before you remove the legacy account.

  • Notify each user immediately after their legacy account is removed. Their e-mail-and-password login no longer works, and they must sign in through Single Sign-On from then on.

Full procedure: Roll out SSO to your team