How can we help? How can we help?

Manage a user’s SSO token in Box+Dice

MRI Box and Dice MRI Box and Dice

Summary

Learn how to update user profiles and reset SSO tokens to resolve sign‑in issues, profile changes, and email address conflicts.

This article covers:


About SSO tokens

A Single Sign On (SSO) token is the secure link between a staff member’s Box+Dice profile and their identity in your SSO provider (such as Google Workspace or Microsoft Entra). 
An SSO token ensures users can sign in quickly without entering separate Box+Dice credentials.

You may need to reset a user’s SSO token if their provider requires re‑authentication, their email address changes, or they need to link their sign‑in to a different staff profile. Resetting the token allows the user to authorise their account again with the correct details.


Reset a user’s SSO token

Reset a user’s token when a user must re‑authorise their account with your SSO provider.

To reset a user’s SSO token:

  • Go to: More > Staff
  • Search and select the staff member’s profile
  • In the top‑right corner, click More > Clear SSO Token
  • Ask the staff member to sign in again

They will be prompted to re‑authorise their SSO provider account.

Tip: Use this process when users report unexpected sign‑in failures, especially after email or permission changes.

Reassign an email address to a different profile

Reassign an email address when a staff member previously used one profile but now needs to sign in with a different one—for example, when moving between offices within the agency.

This process ensures the active profile receives the correct login email and the old profile no longer claims it.

To reassign an email address:

  • Go to: More > Staff
  • Open the old user profile
  • Click More > Clear SSO Token
  • Update the login email of the old profile to something other than the staff member’s active email
    • You may also delete the old email and change the Access level to None if the profile is no longer needed
  • Open the new user profile
  • Update the login email to the staff member’s active email address
  • Ask the staff member to sign in again

They will be prompted to re‑authorise the SSO provider, which will link their authentication to the new profile.

Important: If both profiles contain the same login email, the SSO provider may continue linking to the wrong profile.