Acumatica MFA and SSO: Setup Guide and Licensing

If you’ve ever searched “multi-factor authentication Acumatica” or “Acumatica single sign-on” because you have questions about how Acumatica ensures cloud ERP security, then you’re in the right place.
Doug Johnson August 28, 2022
Acumatica MFA and SSO: Setup Guide and Licensing

Multi-Factor Authentication and Single Sign-On in Acumatica Cloud ERP: What They Are and How to Set Them Up

Acumatica Cloud ERP supports two key access security tools: built-in multi-factor authentication (MFA) and single sign-on (SSO) via the Advanced Authentication module. These features are related but serve different purposes, and Acumatica supports them in different ways.

This post explains the difference, walks through both options in Acumatica, and clarifies the licensing you need for each.

What Is the Difference Between MFA and SSO in Acumatica?

MFA and SSO are not the same thing, though the two terms often get tangled together. Understanding the distinction is the first step to choosing the right approach for your organization.

Multi-factor authentication (MFA) requires users to verify their identity with two or more methods before gaining access. Most MFA combines something you know (a password) with something you have (a phone or a hardware key) or something you are (a fingerprint or other biometric).

Single sign-on (SSO) lets users log in once through a central identity provider and access multiple applications without signing in again. SSO is about convenience and centralized identity management.

You can use MFA without SSO. You can use SSO without MFA. Many organizations want both, and Acumatica supports both. The key is understanding which capability comes from where.

Option 1: Built-In Multi-Factor Authentication in Acumatica

Acumatica’s built-in MFA adds a second verification step to the standard login process, without requiring an external identity provider.

When enabled, users confirm their identity at login with a second factor such as:

  • A one-time code sent by email.
  • A push notification approved through the Acumatica mobile app.
  • A text message code, when an SMS provider is configured.

This is the simplest way to add a second layer of security to Acumatica logins. It works entirely within Acumatica and requires no external identity provider.

One important clarification: Acumatica’s built-in MFA secures your Acumatica login specifically. It does not provide single sign-on. If your users need to log in once and move seamlessly between Acumatica and other business applications, Option 2 is the right path.

Option 2: SSO Through an External Identity Provider (Requires Advanced Authentication)

For organizations that manage identities centrally, Acumatica can connect to external identity providers, including Microsoft Entra ID, Google, and Okta, along with other providers that support OpenID Connect.

This capability requires the Advanced Authentication module. Advanced Authentication is an add-on license and is not part of core Acumatica licensing. It enables the features needed to connect Acumatica to external providers, including Active Directory integration and OpenID Connect configuration.

In this model:

  1. Users sign in to your identity provider, which enforces its own MFA policies (authenticator apps, push notifications, hardware keys, biometrics, and more).
  2. The identity provider passes the authenticated user to Acumatica over a secure connection.
  3. The user lands in Acumatica without entering a second set of credentials.

This approach is the best fit for organizations that already run Microsoft Entra ID, Google Workspace, Okta, or a similar platform. You get SSO convenience, and your MFA policies are managed in one place across all your business applications rather than application by application.

Which Option Is Right for Your Business?

The right choice depends on how your organization currently manages user identity and what level of access security you need.

  • Choose built-in MFA if you want a stronger Acumatica login without adopting or expanding an external identity provider. It is quick to enable and keeps everything inside Acumatica. Built-in MFA is better suited for organizations that do not yet use a centralized identity platform and want a straightforward, low-overhead solution.
  • Choose Advanced Authentication with an external provider if your organization already uses a centralized identity platform, needs true single sign-on across applications, or wants advanced MFA options like authenticator apps and hardware keys managed through your provider. Advanced Authentication works best when your team already manages identities through Microsoft Entra ID, Google Workspace, or Okta, and you want consistent MFA enforcement across all your business tools.

Some organizations also layer a VPN in front of Acumatica. The VPN acts as the first authentication layer, and the Acumatica username and password acts as the second. This is a workable approach, but for most businesses, one of the two options above will be simpler to manage long-term.

How to Set Up SSO with Advanced Authentication in Acumatica

If you choose the external provider route, here is what implementation looks like at a high level.

Step 1: Confirm Your Licensing. Work with your Acumatica partner to add the Advanced Authentication module to your license if you do not already have it.

Step 2: Prepare Your Identity Provider Accounts. Every user who will access Acumatica needs an account with your identity provider, with your desired MFA policies enabled on the provider side.

Step 3: Configure the Connection. Set up Acumatica as an application in your identity provider, then enter the client credentials in Acumatica’s OpenID Providers configuration. Acumatica’s help documentation provides detailed steps for supported providers. SaaS customers may need assistance from Acumatica for configuration changes.

Step 4: Link External Identities to Acumatica Users. When an identity arrives from your provider, Acumatica needs to know which user it belongs to. Configure this mapping on the User Profile screen or the Users screen under the External Identities tab. Auto-provisioning options are also available.

Step 5: Tighten the Login Page. To prevent users from bypassing your MFA policies, consider removing the standard username and password option from the login page so all access flows through your identity provider.

Planning for Costs

Budget for a few items when planning your rollout:

  • The Advanced Authentication module, licensed through Acumatica for external provider SSO.
  • Identity provider accounts for each user, often already covered if your organization uses Microsoft 365, Google Workspace, or a similar platform.
  • Implementation services from your Acumatica partner, or from Acumatica for SaaS deployments, to configure and test the integration.

Frequently Asked Questions

Does Acumatica’s built-in ERP multi-factor authentication work with all login methods?

Acumatica’s built-in MFA applies to standard Acumatica logins. It supports one-time email codes, push notifications via the Acumatica mobile app, and SMS codes when an SMS provider is configured. It does not apply to logins handled by an external identity provider, as those are governed by the provider’s own MFA policies.

Do I need the Advanced Authentication module to use MFA in Acumatica?

No. Acumatica’s built-in MFA is available without the Advanced Authentication module. The Advanced Authentication module is only required if you want to connect Acumatica to an external identity provider for SSO. If you only need a second verification step at Acumatica login, the built-in option is sufficient.

Can Acumatica enforce MFA for all users automatically?

When using built-in MFA, administrators can require the second factor for all users through Acumatica’s security settings. If needed, you can make user-specific exceptions for API users and trusted devices. When using an external identity provider via Advanced Authentication, MFA enforcement is configured within the identity provider itself, such as Microsoft Entra ID or Okta, and applies consistently across all connected applications.

What happens if a user loses access to their MFA device?

Recovery options depend on which MFA method your organization uses. For built-in MFA, administrators can reset a user’s second factor through Acumatica. For external provider SSO, recovery is handled within the identity provider’s own account management tools.

Security That Fits Your Business

Acumatica’s cloud ERP software and modern platform gives you a clear choice: straightforward MFA built into the product, or full SSO with your existing identity provider through the Advanced Authentication module. Either path meaningfully strengthens access security. The right one depends on how your organization manages identity today and where you want it to go.

If you have questions about MFA, SSO, or the Advanced Authentication module, contact your Acumatica partner or reach out to us today.

Blog Author

Categories