Last updated on May 27, 2025
Does Vacation Tracker offer SSO (Single Sign-On)?
Yes — and for most teams, it's already on. If your account uses the Slack, Microsoft Teams, or Google Workspace integration, you're signing in via SSO automatically: Vacation Tracker hands you off to your identity provider for authentication and trusts whatever they say. No separate VT password to manage.
Which Integrations Use SSO?
Three of Vacation Tracker's four sign-in paths are SSO-backed by default. The fourth (Email Only) uses VT's own login with optional MFA on top.
Slack SSO
Click Sign in with Slack on the login screen. You're routed to Slack's OAuth flow, which authenticates you against your workspace and returns you to Vacation Tracker.
Microsoft Teams SSO
Click Sign in with Microsoft and you're sent to the Office 365 / Microsoft Entra login first to enter your Microsoft credentials, then bounced back into Vacation Tracker.
Google Workspace SSO
Click Sign in with Google to use your Google Workspace account. Google handles the authentication and Vacation Tracker accepts the result.
Email Only No SSO
For teams that don't use Slack, Teams, or Google Workspace, VT supports email + password sign-in with its own MFA option layered on top. See Does Vacation Tracker have MFA?
What That Means in Practice
Multi-Factor Authentication (MFA) for SSO Users
For Slack, Microsoft Teams, and Google Workspace integrations, MFA is configured in the identity provider's settings, not inside Vacation Tracker. Whatever MFA policy the provider enforces — TOTP app, SMS code, security key, push notification — runs at the provider login step before VT sees you. Set it up here:
Slack two-factor authentication
Microsoft two-step verification
Google 2-Step Verification
Common Questions
No. If your Vacation Tracker workspace is set up under a Slack, Microsoft Teams, or Google Workspace integration, every User automatically signs in through SSO. There's no toggle to flip — it's the only way they can sign in for that integration path.
The four supported sign-in paths are Slack, Microsoft Teams (via Microsoft / Office 365), Google Workspace, and Email Only. SAML / OIDC integrations with third-party identity providers like Okta, OneLogin, or JumpCloud aren't currently part of the standard sign-in options. If your IdP federates into Microsoft Entra or Google Workspace, you can usually still benefit from those rules at the IdP layer when Users sign in through the Microsoft or Google option. For dedicated SAML integration questions, contact Support.
Switching integrations (e.g. Slack → Microsoft Teams) is a migration, not just a sign-in change. Vacation Tracker has a dedicated migration flow that moves your data to the new integration. See How Do I Migrate My Account? If you stay on the same integration but change identity provider settings inside it (e.g. switch Microsoft tenant), Users keep working as long as their email addresses match.