Enterprise SSO and SCIM
Enterprise plan organizations can replace per-user logins with their own identity provider: SAML or OIDC for sign-in, and directory sync (SCIM) for automatic user provisioning. SSO is included in Enterprise; directory sync is a paid add-on. See Billing and tiers.
Every organization, on any plan, already has email plus password and Microsoft work account sign-in. Enterprise SSO is for organizations that need their own IdP, enforced centrally.
What You Get
| Capability | Effect |
|---|---|
| SAML / OIDC SSO | Users sign in through your IdP (Entra ID, Okta, and other SAML/OIDC providers). Access ends when you deactivate them centrally. |
| Directory sync (SCIM) | Users provision and deprovision automatically from your directory |
| Domain verification | Prove ownership of your email domain so sign-ins on it route to your SSO |
Where to Configure
Everything lives under Organization → Enterprise. On plans without enterprise features this page shows basic authentication settings instead.
Until setup is complete, the page runs a setup wizard. After that it shows three status cards: Single Sign-On (with the connected provider), Directory Sync (with the directory type and synced user count), and Verified Domains (verified or pending, per domain).
Each card's Configure or Manage button opens the Admin Portal in a new tab: a hosted console that walks your IT admin through the provider-specific steps. The status cards refresh when you return to the page.
After SSO Is Active
- Microsoft account sign-in is permanently disabled; all users authenticate through your IdP.
- Sign-in method toggles are locked. Only the Allow Guest Users switch stays editable.
- With guest users allowed, admins can still invite users who sign in via password or magic link. With guest users disabled, only users provisioned via SSO or directory sync can access the organization, and the Invites tab disappears from user management.
Verification Checklist
- A test user signs in through the IdP and lands in your organization
- Deactivating that user in the IdP blocks their next sign-in
- With directory sync active: the Users page shows the expected members from the synced groups
Related
- Reference: Users and roles
- Reference: Organization settings for authentication toggles
- Reference: Billing and tiers