Unified login overview

Unified Login is a centralized identity platform that allows users to use a single set of credentials to access multiple Geotab services.

Unified Login is Geotab's centralized identity platform. It replaces the legacy per-database authentication model, enabling users to sign in once and access multiple Geotab services — including MyGeotab, MyAdmin, Marketplace, and more — with a single set of credentials.

Some MyGeotab databases have not yet been migrated to Unified Login. Previously, migration was only possible at the database level — meaning all users on a database had to move together.

The Per-User Migration feature changes this by allowing individual users to be migrated to Unified Login one at a time, independent of database migration status. Administrators can enable migration for any eligible user from the user management page, and users can self-service migrate from their own profile page.

To learn more about Unified Login and Geotab's Centralized Identification and Access Management (CIAM) platform, see the Secure and Seamless Login Experience user guide.

Note: Once Unified Login is enabled for a user, it cannot be reverted to legacy authentication.

Benefits of Unified Login

  • Authenticate once and have access across multiple MyGeotab databases and platforms

  • Enhanced security with centralized password policy enforcement

  • New SSO and MFA capabilities

  • Consistent authentication experience across Geotab products

  • Reduced administrative overhead for credential management

  • Administrators are not able to manage passwords for the email-based accounts

Unified login eligibility

Learn which types of users are eligible for Unified Login.

Only certain users are eligible for per-user migration. The following table summarizes who can and cannot be migrated.

User TypeEligibleNotes
Basic auth usersYesMust have a valid email address
SAML usersNoAlready use federated identity provider
Service accountsNoNon-interactive accounts are excluded from Unified Login
Legacy MyAdmin usersNoMyAdmin authentication is managed separately

Unified login migration states

Each user's migration progress is tracked through a set of states visible in the Unified Login status indicator on the User Edit page.

The status indicator displays one of the following states.

StateStatus IndicatorDescription
Not migratedNo indicatorDefault state for non-migrated users. Migration has not been started. You can enable Unified Login for this user.
Pending — Awaiting LoginUnified Login PendingMigration has been enabled. The user will be migrated automatically the next time they log in. No further action is needed.
Pending — Awaiting Email VerificationUnified Login PendingA verification email has been sent. The user must click the link in the email and set their password to verify their account and complete migration.
Unified Login EnabledUnified Login EnabledMigration is complete. The user now signs in with Unified Login.
Migration ErrorMigration ErrorMigration could not be completed. An error message with details and next steps is shown in the status indicator.

Enabling Unified Login for users

Learn how to trigger Unified Login migration for users as an administrator.

Administrators can trigger Unified Login for individual users. For more information on triggering migration for your own account, see Opting into Unified Login as a user.
  1. Navigate to People > Users & Driversin the main menu.
  2. Select the user you want to trigger Unified Login for from the user list.
  3. At the top of the page, select Manage user > Enable Unified Login.
    The User Edit page showing the manage user dropdown menu and option to enable Unified Login.
The system will attempt to migrate the user. You'll receive one of the following results:
  • Success - Immediate Migration: The status indicator changes to Unified Login Enabled. The users Geotab services are now connected under a single login. No further access to required.The User Edit page showing a user with the successful Unified Login Enabled badge next to their user name.

  • Success - Pending (Awaiting Login): Migration has been enabled. The user will be migrated automatically the next time they log in. No action is required from the user - migrations happens seamlessly during the next normal login process.The User Edit page showing a user with the Unified Login pending status indicator showing that migration will be completed on the user's next log in.

  • Success - Pending (Awaiting Email Verification): A verification email has been sent to the user. The user must click the link in the email and set their password to complete migration.The User Edit page popup showing that the user must verify their email before migration completes.

  • Error: An error message is displayed with guidance on how to correct the issue. See Unified Login error codes for more details on errors codes.The User Edit page popup showing an example of a duplicate account error during migration.

Opting into unified login as a user

Learn how to opt your own account into the unified login migration process.

Users can opt themselves into Unified Login without needing an administrator. Administrators can use the Enabling unified login for users workflow to enable it for other users.
  1. Select the profile icon in the top right corner and click Profile.
  2. Click the Enable Unified Login button at the top of the page.
    Note: The Enable Unified Login button is only visible if you are eligible for Unified Login.
Migration is triggered immediately. You'll receive one of the following results:
  • Success - Immediate Migration: Your account is already in the system and verified, and migration is completed immediately.The User Edit page popup showing successful migration and Unified Login enabled for your user account.

  • Success - Email verification required: Your email has not been verified. A verification email is sent to your account, where you can follow the link to set your new password and complete migration.The User Edit page popup showing that migration is pending and the user must verify their email before it completes.

  • Error - Something went wrong with the migration. You'll receive an error message with guidance to correct the issue or contact your administrator for assistance.The User Edit page showing the Unified Login failed status indicator and guidance on how to resolve the issue.

Migrating a user requiring email verification

Learn how to complete migration for users that require email verification.

Users with unverified email addresses are required to verify their emails as part of the migration process. When Unified Login is enabled for these users, it automatically triggers the verification process.
  1. Once Unified Login is enabled, a verification email is sent to the user's email address on file.
  2. The user clicks the link in the email to set their password.
  3. Once the user's password is confirmed, the migration is completed.
The verification email explains that the user must verify their email by setting a password. The migration process will not be completed until the user sets a password and their email is verified.

Additional migration paths

Unified Login can be triggered by several additional migration paths.

While most users can enable Unified Login using the administrator-enablement or user opt-in workflows, migration can also occur using the following paths:

PathDescription
Password change triggerIf an eligible user changes their password in MyGeotab, migration may be triggered automatically using the new password. If migration does not complete during this process, the password change still succeeds and the user remains eligible for automatic migration at their next login.
Automatic migration at loginWhen a user with migration enabled logs into MyGeotab, migration is attempted automatically during the login process. If successful, the user is seamlessly migrated without any visible change to their login experience. If migration fails, the error details are shown in the status indicator on the user management page.

Unified Login error codes

Learn more about Unified Login error codes and what they mean.

If migration fails, the status indicator or the UI will display an error code with guidance. The following table lists all possible error codes and their resolutions.

Error codeCauseResolution
DUPLICATE_USERNAME

Another user already has this username.

Contact your administrator to resolve the username conflict.

INVALID_USERNAME_CHARS

The username contains unsupported characters.

Contact your administrator to update the username to use only supported characters, then retry migration.

PASSWORD_POLICY_VIOLATIONThe current password does not meet the required password policy.

Change your password to one that meets the policy requirements. The self-service flow will show a password reset prompt automatically.

WRONG_AUTH_TYPE

The user account type does not support migration.

Only standard password users are eligible for per-user migration. SAML, service account, and MyAdmin users cannot be migrated.

Known limitations for Unified Login

Learn more about known limitations for Unified Login.

The following limitations apply to the V1 release of per-user migration.

LimitationDetails
Bulk migrationNot available. Administrators must enable migration one user at a time from the user management page.
Users list filteringThe Users list cannot be filtered by migration state. Administrators must open each user individually to check their status.
Error displayIf migration fails during login, the error details are shown in the status indicator on the user management page.