Thrive Apprentice can publish and restrict a safety course on WordPress, and Teams can link people to it. That does not give the course Microsoft single sign-on by default. Genuine Teams SSO requires a supported identity integration, tenant configuration and testing with the actual user accounts.
Do not call the result compliant merely because a learner can open it. Safety compliance depends on the content, assessment, records, policy and jurisdiction as well as the technology.
Prerequisites
Before building, confirm:
- an owned WordPress site with HTTPS
- Thrive Apprentice installed and activated
- a WordPress administrator who can configure the plugin
- a named owner for the safety content
- a decision on learner identity and account removal
- the completion evidence your organisation requires
- an approved Microsoft Entra ID integration if SSO is required
- a test account with no administrator privileges
Thrive's current documentation says access restrictions operate at the Product level. Create the course, then place it in a product and configure access rules before publishing protected material.
Step 1: Define the evidence before the pages
Write down what a completed record must contain. For example:
- learner identity
- assigned content and version
- completion or assessment result
- date and time
- expiry or refresher date, if applicable
- corrections or retakes
- export and retention owner
Thrive Apprentice can provide course and access features, but this article does not assert that its records satisfy a regulator or your employer's policy. Ask the responsible health and safety, legal or compliance specialist to approve the evidence model.
Step 2: Create the course in Thrive Apprentice
Thrive's documented route is:
- In WordPress, open Thrive Dashboard > Thrive Apprentice.
- Complete the setup wizard if this is a new installation.
- Open Courses and select Add course.
- Add the course title and description.
- Add modules, chapters and lessons as needed.
- Add the lesson content in Thrive Architect.
- Keep the course unpublished until access has been configured and tested.
Use short sections, plain language and content appropriate to the workplace. Version the source material outside the page builder as well, so an auditor can identify what a person was shown.
Step 3: Protect access
Create or select a Thrive Apprentice Product and add the course to it. Then configure the login page and access restriction rules.
Test at least these states:
- signed out
- signed in without access
- signed in with access
- content not yet available
- access removed
Thrive documents manual access recovery through the Members area when an entitled user does not receive access. Record that recovery path for support staff.
Step 4: Decide what "Teams SSO" means
There are three distinct experiences:
- A link in Teams: the browser opens WordPress and may ask the learner to sign in.
- A website or custom tab: WordPress is shown inside Teams, but its own authentication can still prompt.
- A Teams app with SSO: a registered Teams app and Microsoft Entra ID application use Microsoft's supported token flow, with server-side validation and permissions configured.
Only the third is Teams SSO in Microsoft's platform sense. A WordPress identity plugin may offer Microsoft 365 sign-in, but its configuration, token handling, user matching, licensing and support are vendor-specific. Check its current documentation and have the tenant owner approve the app registration and permissions.
Microsoft's Teams tab SSO documentation says the flow needs an Entra ID app registration and Teams app configuration. It also warns that SSO does not work in all situations, including some anonymous and guest contexts.
Step 5: Surface it in Teams
Prefer the least complicated route that meets the need:
- Pin an approved link in a channel post or suitable tab.
- Use a vendor-supported Teams app if one exists.
- Build a custom Teams tab only when somebody will own its manifest, domains, identity code and deployment.
Test desktop, web and mobile if those clients are in scope. Conditional Access, browser cookie restrictions and guest identity can change the sign-in experience.
Step 6: Test failure and recovery
Run these checks with non-admin accounts:
- A learner receives access and can open the correct content.
- Another signed-in user cannot open it.
- A failed or expired sign-in has a recoverable route.
- Completion is attributed to the correct person.
- Access removal takes effect.
- Completion data can be exported and interpreted.
- A backup can be restored in a test environment.
Take screenshots or logs of the results without exposing personal or sensitive information.
Proof boundary
Completing these steps proves only that the tested accounts can follow the configured path. It does not prove regulatory compliance, universal SSO, licence suitability or recovery until the relevant specialists approve them and the restore is tested.
For help reviewing a Teams-linked content service and its identity boundaries, join the SharePoint & Teams Admins Space.
