Draft ready to testEnterpriseDraft saved

Account settings ยท Security

Enterprise SSO setup

Connect an identity provider, review workspace access, and test the rollout before requiring SSO for verified company domains.

Setup readiness60%

Connection

Choose an identity protocol

Connection complete

Choose the protocol the customer identity provider expects.

Login routing

Company domains

People using these domains will be routed through SAML 2.0 after activation.

1 verified1 pending
northstar.examplenorthstar-analytics.example

Add verified company domains or begin a DNS ownership check.

Provider metadata

IdP configuration

Paste server-issued metadata and keep certificate validation, expiry, and key rotation in the backend.

Paste signed IdP metadata. Store the certificate fingerprint and expiration on the server.

Provisioning

Map IdP groups to workspace roles

Review imported groups and choose the least-privileged role each group needs before testing access.

1 needs review
Okta - Product adminsOkta - AnalystsOkta - Finance reviewers

Choose imported IdP groups to include in the initial rollout.

Okta - Product admins

42 users

Imported identity-provider group

Synced

Okta - Analysts

188 users

Imported identity-provider group

Synced

Okta - Finance reviewers

19 users

Imported identity-provider group

Review

Rollout safety

Activation controls

Confirm recovery and communication safeguards before requiring SSO for company domains.

Preserve password fallback during rolloutKeep two break-glass administrators outside forced SSO during the migration window.
Notify administrators before activationSend the activation date, affected domains, recovery contact, and next-sign-in behavior.
Require SSO for verified domainsAfter activation, route people with verified company domains through the configured identity provider.

Implementation guidance

Before enforcement

Keep at least two break-glass admins outside forced SSO until the first successful production login and support handoff are confirmed.
Send a preview email with the activation date, approved domains, recovery contact, and what changes at the next sign-in.
Allow fallback for a short migration window, then require SSO for verified company domains after the customer confirms adoption.

SSO test passed

The assertion matched this draft configuration. Review the exact activation scope before enforcing login.

Matched claims
Email, name, groups, certificate fingerprint, and recipient URL were accepted.
Activation scope
1 verified domain and 3 mapped groups.

Activate enterprise SSO?

This changes the next sign-in for people using verified company domains. Password fallback remains available to emergency administrators.

Protocol
SAML 2.0
Verified domains
1
Mapped groups
3