Skip to main content

Transitioning Your SSO/SAML to Thrive 2.0

Written by Kelsey Chan

Upgrading to Thrive 2.0 requires a few updates to your Single Sign-On (SSO) configuration because the new platform operates on a different web address than Thrive 1.0. While Thrive handles the bulk of the underlying data migration, your IT team will need to make a few quick adjustments to your Identity Provider (IdP) to ensure a seamless cutover.
​

What Stays the Same (What Thrive Handles)

You do not need to rebuild your entire SSO infrastructure. The following elements will carry over automatically or remain entirely unchanged:

  • The end-user login experience: Your team will continue to select "Login with SSO," use their existing Multi-Factor Authentication (MFA), and bypass the need for a Thrive-specific password.

  • Your core Identity Provider (IdP): Aside from updating two specific routing fields, you do not need to re-authorize your IdP.

  • Existing certificates and login URLs: Your current IdP login URL and signing certificate will remain unchanged.

  • Permissions and access: Thrive internally copies over your existing role mappings, allowed email domains, and SSO enforcement settings.

Your IT Checklist: What You Need to Do

To connect your Identity Provider to Thrive 2.0, your IT administrator needs to configure a new connection alongside your existing one.

  1. Create a new application: Add Thrive 2.0 as a second, completely separate application entry in your IdP. Please do not edit or overwrite your live Thrive 1.0 application.

  2. Update the Entity ID: Locate the field for Entity ID (which may also be called Audience URI or Issuer in your system) and enter the new Thrive 2.0 value provided by your Customer Success Manager.

  3. Update the ACS URL: Locate the field for ACS URL (which may also be called Reply URL or Single Sign-On URL) and enter the new Thrive 2.0 value provided by your Customer Success Manager.

  4. Send the Metadata: Once the new application is configured, download the new IdP metadata XML file and email it to your Thrive representative.

Managing Dashboard Tiles (IdP-Initiated Logins)

If your organization uses an IdP-initiated login—meaning your employees launch Thrive by clicking a tile in a dashboard like Okta or Entra—you must ensure that tile points to the newly created Thrive 2.0 application. Once the new connection is live and confirmed, you can safely disable your old Thrive 1.0 dashboard tile.


​

Frequently Asked Questions

  • Can Thrive just redirect our old URLs automatically? No. Because Thrive 2.0 runs on an entirely new web address, we cannot silently redirect your existing setup without these required IT updates.

  • Does this change how the Outlook Add-in works? Not yet. The Outlook add-in currently still requires users to sign in with an email and password, exactly as it functioned in Thrive 1.0. Redesigning the add-in to honor tenant SSO and MFA policies is planned for a future update.

Did this answer your question?