Security is always top of mind for PeopleSoft customers. Over the years, customers have continued to modernize how users access enterprise applications, often by centralizing authentication through enterprise identity providers and adding stronger verification options for sensitive access.
With our upcoming PeopleTools 8.63 release, we are adding two important security capabilities that will help customers move in that direction: SAML 2.0 support for single sign-on and two-factor (2FA) authentication using time-based one-time password (TOTP).
These features address different parts of the sign-on experience, but they share a common goal: helping customers strengthen access to PeopleSoft while fitting into the security models they already use across the enterprise.
SAML 2.0 Support
Many organizations rely on identity providers to manage authentication across enterprise applications. PeopleTools 8.63 will add native support for SAML 2.0 single sign-on, making it easier for customers to integrate PeopleSoft with identity providers that support the SAML 2.0 standard.
Once configured, PeopleSoft will be able to support both identity provider-initiated and service provider-initiated sign-on flows. This means users will be able to start from an identity provider application portal, or they can start from a PeopleSoft URL, a notification email, or another deep link. If authentication is required, PeopleSoft can redirect the user to the identity provider and then return the user to the original PeopleSoft target after successful sign-on.
This is important because single sign-on is not just about convenience. It helps customers align PeopleSoft access with their broader identity strategy, reduce the need for additional sign-on layers, and provide a more consistent access experience across applications.
PeopleTools will provide the SAML 2.0 framework and configuration pages customers need to assemble the integration for their chosen identity provider.


Two-Factor Authentication Using Time-Based One-Time Password
PeopleTools 8.63 will also add support for two-factor authentication (2FA) using time-based one-time password (TOTP).
With TOTP, customers will be able to add an additional verification step after successful primary authentication. Users will verify access with a time-limited code from a registered authenticator app. This gives customers a standards-based way to strengthen access with authenticator apps that support TOTP.
Users will be able to enroll and manage their authenticator devices from the My Two-Factor Verifications page. They can also register multiple devices, such as a phone or tablet, so they have another verification option available when needed.
Administrators will enable TOTP by configuring and activating the security policy and TOTP configuration, and by enabling the required web profile custom property for the TOTP verification flow.
PeopleTools 8.63 will also provide an API that customers can use to invoke two-factor authentication during selected transactional events. This will allow customers to add an additional verification step for sensitive actions, such as updating direct deposit information, changing personal identification details, or other business processes that require stronger protection.


Strengthening Access to PeopleSoft
SAML 2.0 and TOTP are foundational security capabilities for modern enterprise applications. They help customers align PeopleSoft with their broader identity and access strategy, strengthen verification where it matters, and provide a more consistent sign-on experience for users.
PeopleTools 8.63 will give customers more options: integrate PeopleSoft with the identity provider that supports their implementation, add TOTP-based verification after primary authentication, extend stronger verification to sensitive transactions.
Look for these security enhancements in PeopleTools 8.63!
