We set up SSO (Single Sign-On) for Bitrix24 so your employees can forget about multiple passwords. Imagine: morning, an employee logs into Windows — one password, opens email — another, accesses Jira — a third, then Bitrix24 — a fourth. Passwords are lost, written on sticky notes, and IT spends hours on resets. SSO solves this: one login via a corporate Identity Provider, like Azure AD, Keycloak, or ADFS — and access to all systems. We implement single sign-on turnkey, with guaranteed compatibility and full documentation. Our experience: over 7 years on the market, 80+ successful projects on Bitrix24 and corporate integrations. Request a consultation — we'll assess your project within 1 day and offer the optimal solution.
How SSO for Bitrix24 works
Bitrix24 supports single sign-on via the SAML 2.0 protocol (Security Assertion Markup Language), a standard defined by OASIS. The workflow:
- User opens Bitrix24.
- B24 redirects to the Identity Provider (IdP) — Azure AD, Keycloak, ADFS.
- User authenticates on the IdP (or is already authenticated via Kerberos).
- IdP returns a SAML assertion — a signed XML document with user data.
- B24 verifies the signature, extracts attributes, creates or updates the session.
For cloud Bitrix24, SAML SSO is available on Professional and Enterprise tariffs. For on-premise, via the SSO module.
According to 1С-Битрикс documentation, SSO is supported on Professional and Enterprise tariffs.
Configuration on the Identity Provider side
Regardless of the specific IdP, you need to register Bitrix24 as a Service Provider (SP):
| SP Parameter |
Value |
| Entity ID |
https://your-domain.bitrix24.by |
| ACS URL |
https://your-domain.bitrix24.by/bitrix/tools/saml/acs.php |
| SLS URL |
https://your-domain.bitrix24.by/bitrix/tools/saml/sls.php |
| NameID Format |
urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress |
Azure AD — register an Enterprise Application, configure SAML, upload Federation Metadata XML. Claim rules: user.mail → NameID, user.displayname → Name, user.department → Department.
Keycloak — create a client with SAML protocol, specify Valid Redirect URIs, configure mappers for attributes. Keycloak is convenient for companies that want to host IdP on their own server.
ADFS — add a Relying Party Trust, configure Claim Issuance Policy. A typical issue: the signing certificate expires — you need to monitor the expiration and update it in B24 settings.
| Provider |
Setup Complexity |
Licensing |
Features |
| Azure AD |
Medium |
Included in Microsoft 365 |
Built-in integration with Office 365 |
| Keycloak |
Low-Medium |
Open Source |
Most flexible, can be deployed on-premise |
| ADFS |
High |
Requires Windows Server |
Deep integration with Active Directory |
Certificate exchange
SAML relies on trust between SP and IdP, confirmed by certificates:
- IdP certificate — uploaded to Bitrix24 SSO settings. B24 uses it to verify SAML assertions. When the IdP certificate rotates, you must update it in B24, otherwise authorization breaks.
- SP certificate (optional) — if the IdP requires signed AuthnRequest. Generated in B24 settings and uploaded to the IdP.
Recommendation: during IdP certificate rotation, support both old and new certificates for a transition period.
User attribute mapping
The SAML assertion contains user attributes. B24 extracts them and populates the profile:
- NameID (email) → user login in B24
- FirstName / LastName → first and last name
- Department → department (if mapping to B24 structure exists)
- Groups → groups and roles (for automatic permission assignment)
If a user with that email does not exist in B24, they are created automatically on first login (provisioning via SSO). This is configurable: you can allow auto-creation or require prior registration.
Why configure single sign-on?
The average IT department spends up to 4 hours per week on password resets and account support. SSO reduces this time by 90%. Plus, security improves: no passwords transmitted over the network, centralized access policy. Employees don't write passwords on sticky notes, and system access is immediately revoked upon termination. Compare: deploying Keycloak takes 1-2 days, while ADFS requires setting up Windows Server and configuration, which is 2-3 times longer. Azure AD is a compromise if the company already uses Microsoft 365.
What's included
- Audit of current infrastructure and selection of Identity Provider.
- Registration of Bitrix24 as a Service Provider.
- SAML 2.0 configuration on the IdP side.
- Certificate exchange and trust testing.
- Attribute mapping: email, name, department, groups.
- Automatic user provisioning setup.
- Operations documentation and certificate rotation procedure.
- Administrator training.
Process
- Analysis — we study your infrastructure, select the appropriate IdP.
- Design — we develop the SSO scheme, agree on mapping.
- Implementation — we configure the SAML connection, exchange certificates.
- Testing — we verify authorization, debug errors.
- Deployment — we hand over documentation, conduct training.
Timeline and cost
Cost is calculated individually, depending on the chosen Identity Provider and required integration depth. Estimated timeline: from 3 to 10 business days. Get an accurate estimate — contact us.
Over 7 years on the market, 80+ successful projects on Bitrix24 and corporate integrations — we guarantee quality and post-deployment support. Reach out for a free consultation — we'll propose a solution tailored to your infrastructure.
How a corporate portal on Bitrix24 solves the problem of information chaos?
Employees spend up to 2 hours a day searching for files, emails, and solutions. Tasks get lost in dozens of chats, approvals get stuck for weeks. The manager learns about missed deadlines only at a meeting. A corporate portal on Bitrix24 ties every message, document, and task to a single context. You get a transparent picture of work: who is working on what, which stages, where bottlenecks are. Wikipedia: Information silo describes how unorganized data reduces productivity – a portal cuts that loss by 60–70%.
We will evaluate your project for free – contact us to get the architecture in 2 days. A medium‑sized company typically saves 2.5 million rubles annually after deployment (based on our projects).
What does the portal offer in daily work and why is it better than messengers?
In messengers, information is unstructured – discussions get buried within a week. On the portal, every message is tied to a task, project, or document. Employees spend up to 30% of their work time searching for data (McKinsey). The portal reduces this time by 2–3 times thanks to structured repositories and full‑text search.
Communications. Activity stream, messenger, and video calls are tied to specific tasks. Any discussion can be found six months later – in a messenger it would be buried within a week.
Tasks and projects. Kanban, Gantt, checklists, dependencies, time tracking. Each employee's efficiency is visible in reports – no need to wait for a meeting.
Document flow. Approval routes through the business process designer: leave request → manager → HR → accounting. Electronic signature, versioning, deadline control. Integration with electronic document management (SBIS, Diadoc) via REST API.
HR. Onboarding of new employees, leave/travel requests, organizational structure, absence schedule. An employee knows where to go from day one.
Knowledge base. Bitrix24 wiki engine: regulations, instructions. Knowledge does not leave with departing employees.
Implementation example. For a manufacturing company with 320 employees, we deployed a portal with integration of 1C:SALARY AND HR MANAGEMENT and Active Directory in 4 months. Travel request approval time decreased from 3 days to 4 hours. Savings on employee idle time amounted to 1.5 million rubles per year. Managers receive automatic reports on department efficiency. Customer response time decreased by 20%. Portal payback period is 7 months.
How does integration with 1C and Active Directory accelerate HR management?
Integration with 1C:Enterprise via the b24connector module or custom REST handler: a leave request is approved on the portal through a business process and automatically enters 1C:SALARY AND HR MANAGEMENT for vacation pay calculation. Active Directory (SSO via the ldap module) – the employee account is created once in AD and synchronized to the portal, email, VPN. Upon dismissal, it is blocked everywhere. Manual account creation is eliminated, errors are minimized.
Types of corporate portals and key integrations
| Type |
Purpose |
Key Feature |
| Intranet |
Internal communications and services |
News, phone directory (sync with AD), meeting room booking, IT requests via BP |
| HR portal |
HR management and development |
Profiles, KPI/OKR on custom HL blocks, training, electronic document flow |
| Knowledge portal |
Documentation and regulations |
Categorization, tags, ratings, subscriptions to updates |
| Extranet |
Work with partners and contractors |
Granular permissions via CGroup and extranet module, access without VPN |
| Holding portal |
Management of multi‑company structure |
Separate workspaces, consolidated reporting, cross‑cutting BPs |
Additional integrations that deliver real value:
- Email: Exchange via EWS API or IMAP, calendar synchronization, creating a task from an email.
- IP telephony: Asterisk, Mango Office, Zadarma via REST API – calls from the portal, contact card, call recording.
- Video conferencing: built‑in video calls or integration with Zoom/Teams via marketplace.
- EDI: SBIS, Diadoc via REST API – fully electronic document flow with counterparties.
Security and compliance with Federal Law 152‑FZ
The portal contains personal data, financial reports, strategic plans. We guarantee protection:
- role model via CGroup and section‑level permissions;
- two‑factor authentication (OTP, Yandex.Key, SMS);
- audit of all actions (b_event_log);
- TLS encryption for transmission and disk encryption;
- full compliance with Federal Law No. 152‑FZ "On Personal Data".
How is implementation carried out? Step‑by‑step plan
| Stage |
Duration |
What we do |
| 1. Audit |
2–3 weeks |
Interviews, process analysis, architecture, integration plan |
| 2. Setup and customization |
3–6 weeks |
Structure, roles, BPs, branding (CSS template) |
| 3. Integrations |
2–4 weeks |
1C, AD, email, telephony, EDI |
| 4. Data migration |
1–2 weeks |
Documents, directories, employees from current systems |
| 5. Training and pilot |
1–2 weeks |
Administrators, key users, pilot of 20–30 people |
| 6. Scaling |
2–4 weeks |
Connecting departments, fine‑tuning based on feedback |
- Audit — we record current processes, measure time losses.
- Design — choose portal type, plan integrations.
- Implementation — configure business processes, permissions, interface.
- Test — pilot group tests scenarios, we fix issues.
- Launch — connect all employees, train, hand over documentation.
What you receive after implementation
- Project documentation: architecture, integration scheme, business process diagrams.
- Configured portal with all integrations (1C, AD, telephony, EDI).
- Business process descriptions and instructions for administrators and users.
- 30 days of technical support after launch.
- Access to our knowledge base and migration scripts.
Post‑launch support: how to prevent the portal from becoming obsolete
After six months, many portals become abandoned. To avoid this, we offer packages with fixed SLA and a dedicated administrator. Performance monitoring, platform updates, user administration, development of new modules. Our team has over 10 years of experience and more than 50 implemented corporate portals on Bitrix24. We are a certified 1C‑Bitrix partner, guaranteeing quality and deadlines.
Mobile access. Native Bitrix24 app (iOS/Android) with push notifications, tasks, chats. Responsive web interface for extranet users (no app installation required). Offline access to documents and tasks, sync when connectivity is restored.
Order a turnkey corporate portal implementation
Schedule a free audit – we will evaluate your project, propose architecture, and give clear timelines. Get a comprehensive proposal and see that the portal pays for itself within the first six months. Contact us today.