If your organization runs more than one Recruitee company, users normally have to log out and log back in to move between them when using SSO. By connecting all of your companies to a single Enterprise application in Microsoft Entra ID, you can let them switch companies directly in the app. This article explains what to add to your existing SSO configuration to make that possible.
📌 Note: This article builds on a working SSO setup. If you haven’t configured SSO yet, start with How to set up SSO with Microsoft Entra ID and come back here afterwards.
How it works
One Enterprise application can serve all of your companies, but Microsoft Entra ID needs to tell them apart. You do this by giving every company its own pair of values in the Basic SAML Configuration:
A unique Identifier (Entity ID), chosen from the list of values Tellent accepts.
A unique Reply URL (Assertion Consumer Service URL), based on that company’s subdomain.
You then use the same metadata file for every company, and match each company in Recruitee to the Entity ID you gave it in Microsoft Entra ID.
Control who can access which company
Because all of your companies sit behind one Enterprise application, access is granted at the application level rather than per company.
⚠️ Important: Users and groups are assigned to the Enterprise application as a whole, not to individual companies. Anyone assigned to the application can technically sign in to any company connected to it.
Two settings keep this under control:
Share only the sign-in link a user needs. Each company has its own sign-in URL:
https://auth.tellent.com/sso/sign-in/YOUR_COMPANY_NAME. Send people the link for their own company instead of a general one, so they land in the right place.Set a low-permission default role. When you enable SSO for a company in the Tellent Settings, you choose the role new users get the first time they sign in. Pick the most limited role that still lets people do their work, then change individual users' roles afterwards.
📌 Note: If you pick a role with restricted access to jobs or talent pools, such as Reviewer, you’ll need to assign jobs and talent pools to those users manually in Recruitee.
Add an Entity ID for each company
Each company needs its own Entity ID. Use the values below — Tellent only accepts these, so you can’t invent your own.
In the Microsoft Entra ID portal, open your Recruitee Enterprise application and go to Single sign-on.
Next to Basic SAML Configuration, click Edit.
Click Add identifier and enter one of the accepted values for your second company.
Repeat for every additional company, using a different value each time.
Click Save.
Accepted Entity IDs:
tellent
tellent-1
tellent-2
tellent-3
tellent-4
tellent-5
tellent-6
tellent-7
tellent-8
tellent-9
tellent-10
urn:x-tellent:services:tellent.com
urn:x-tellent:services:tellent.com-1
urn:x-tellent:services:tellent.com-2
urn:x-tellent:services:tellent.com-3
urn:x-tellent:services:tellent.com-4
urn:x-tellent:services:tellent.com-5
urn:x-tellent:services:tellent.com-6
urn:x-tellent:services:tellent.com-7
urn:x-tellent:services:tellent.com-8
urn:x-tellent:services:tellent.com-9
urn:x-tellent:services:tellent.com-10
💡 Tip: Keep a note of which Entity ID belongs to which company. You’ll need to enter the matching value again when you set up SSO in Recruitee.
Add a Reply URL for each company
Every company also needs its own Reply URL, which points to that company’s subdomain in Recruitee.
In the Basic SAML Configuration panel, click Add reply URL.
Enter
https://auth.tellent.com/sso/sp/consume/YOUR_COMPANY_NAME, replacing YOUR_COMPANY_NAME with the company’s Recruitee subdomain — the same one used for its career site.Repeat for every additional company.
Click Save.
For example, a company on the subdomain acme uses https://auth.tellent.com/sso/sp/consume/acme.
Connect each company in Recruitee
Once all of your companies are listed in Microsoft Entra ID, you can connect them one by one. All companies share the same metadata file.
Under SAML Certificates in Microsoft Entra ID, download the Federation Metadata XML file.
Log in to the first company in Recruitee and go to the Tellent Settings.
Click Set up SSO for your company and follow the steps.
Upload the metadata XML file and enter the Entity ID you assigned to this company in Microsoft Entra ID.
Repeat for each remaining company, using the same metadata file and that company’s own Entity ID.
⚠️ Important: The Entity ID you enter in Recruitee must match the one you gave that company in Microsoft Entra ID. If the values don’t match, users won’t be able to sign in to that company.
Related articles
Related articles |

