> ## Documentation Index
> Fetch the complete documentation index at: https://docs.stackone.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Single Sign-On

> Let users sign in to StackOne through your organization's SAML identity provider.

StackOne Single Sign-On (SSO) lets the organization's users sign in through its own SAML 2.0 identity provider (IdP). StackOne acts as the SAML service provider (SP), and the IdP authenticates users.

Each organization has one SSO connection, bound to one email domain. Once that domain is verified, anyone whose work email is on it signs in through the IdP instead of with a StackOne password. They can start from the StackOne sign-in page by entering their email, or open the StackOne app from the IdP.

<Note>
  Signing in with SSO doesn't add anyone to the organization. To add users, see [Manage Team](/secure/identity-and-access/manage-team/overview).
</Note>

## Set up an SSO connection

The guide for your SAML IdP takes you through each part of the setup:

* Creating the SAML app in the IdP.
* Registering it in StackOne.
* Verifying the domain.
* Managing the connection afterward.

<CardGroup cols={3}>
  <Card title="Okta" icon="https://stackone-logos.com/api/okta/filled/svg" href="/secure/identity-and-access/authentication/sso/okta" />

  <Card title="Microsoft Entra ID" icon="https://stackone-logos.com/api/microsoft-entra/filled/svg" href="/secure/identity-and-access/authentication/sso/microsoft-entra" />

  <Card title="Other SAML 2.0 provider" icon="shield-halved" href="/secure/identity-and-access/authentication/sso/saml-generic" />
</CardGroup>

## Require SSO

Once the domain is verified, you can require users to sign in through SSO and turn off email and password sign-in.

<Warning>
  Enforcing doesn't check that sign-in works. A misconfigured SAML app, an unassigned user, or a certificate or issuer mismatch still enforces, and **anyone the IdP can't authenticate is locked out**. Before you enforce, open a private or incognito window and complete an SSO sign-in as a user assigned to the app in the IdP, not only your own account.
</Warning>

1. Go to [**Organization > Security > Authentication**](https://app.stackone.com/organization/security/authentication).
2. On the **Enforcement Policy** card, select **Edit policy**.
3. Add the SAML connection to **Enforced methods**.
4. Select **Save changes**.

<Frame>
  <img src="https://mintcdn.com/stackone-60/z6bSbDsMY4CzvXKv/images/secure/identity-and-access/authentication/sso/sso-enforcement.png?fit=max&auto=format&n=z6bSbDsMY4CzvXKv&q=85&s=a394b1855b93a6de831acc3bef954d10" alt="The Enforcement Policy panel under Organization > Security > Authentication, where you add the SSO connection to the enforced sign-in methods." data-og-width="1568" width="1568" data-og-height="191" height="191" data-path="images/secure/identity-and-access/authentication/sso/sso-enforcement.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/stackone-60/z6bSbDsMY4CzvXKv/images/secure/identity-and-access/authentication/sso/sso-enforcement.png?w=280&fit=max&auto=format&n=z6bSbDsMY4CzvXKv&q=85&s=a7b39c7e08c76c0f816027d10286c51b 280w, https://mintcdn.com/stackone-60/z6bSbDsMY4CzvXKv/images/secure/identity-and-access/authentication/sso/sso-enforcement.png?w=560&fit=max&auto=format&n=z6bSbDsMY4CzvXKv&q=85&s=597a234aa42bed2052af038435f0dff7 560w, https://mintcdn.com/stackone-60/z6bSbDsMY4CzvXKv/images/secure/identity-and-access/authentication/sso/sso-enforcement.png?w=840&fit=max&auto=format&n=z6bSbDsMY4CzvXKv&q=85&s=9994a404690e24129812678a07c1a6c1 840w, https://mintcdn.com/stackone-60/z6bSbDsMY4CzvXKv/images/secure/identity-and-access/authentication/sso/sso-enforcement.png?w=1100&fit=max&auto=format&n=z6bSbDsMY4CzvXKv&q=85&s=b1f516617c09c88d60956580ff8bbc7f 1100w, https://mintcdn.com/stackone-60/z6bSbDsMY4CzvXKv/images/secure/identity-and-access/authentication/sso/sso-enforcement.png?w=1650&fit=max&auto=format&n=z6bSbDsMY4CzvXKv&q=85&s=56bab4636580642a5d643477f3626e63 1650w, https://mintcdn.com/stackone-60/z6bSbDsMY4CzvXKv/images/secure/identity-and-access/authentication/sso/sso-enforcement.png?w=2500&fit=max&auto=format&n=z6bSbDsMY4CzvXKv&q=85&s=974ba1a9307fffdf563f7d2f10477826 2500w" />
</Frame>

Enforcement takes effect as soon as you save. Anyone whose session didn't come through an enforced method, including you, is asked to sign in through the IdP the next time they load a page or switch to the organization.

<Note>
  Locked out after enforcing? An **Organization Admin** who can still reach the dashboard can remove the method from the **Enforcement Policy** to restore password sign-in. If no one can get in, contact StackOne support.
</Note>

## Next steps

<CardGroup cols={2}>
  <Card title="Just-in-Time Provisioning" icon="user-plus" href="/secure/identity-and-access/manage-team/jit">
    Add users who aren't members yet when they sign in, and map an attribute to organization admin.
  </Card>

  <Card title="SCIM Provisioning" icon="arrows-rotate" href="/secure/identity-and-access/manage-team/scim/overview">
    Provision and deactivate members automatically from the IdP.
  </Card>

  <Card title="Groups" icon="users" href="/secure/identity-and-access/roles-and-groups/groups">
    Grant many members the same project or account access at once.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.