# SSO, SAML, and SCIM provisioning

> Enable single sign-on on Workload: SAML (Okta, Auth0, generic), Azure AD, Google Workspace, JIT provisioning, and SCIM. Steps and FAQ.

- HTML: https://www.simpleworkload.com/en/integrations/sso
- Markdown: https://www.simpleworkload.com/en/integrations/sso.md

## How do you enable SSO on Workload?

In Settings > SSO, choose your provider: Azure AD or Google Workspace (OAuth), or Okta, Auth0, and any generic SAML provider. For SAML, import your provider's metadata file or enter the entity ID, SSO URL, and certificate, then enable SSO. Just-in-time (JIT) provisioning is available from the Business plan and SCIM provisioning on the Enterprise plan.

SSO/SAML (one provider) from the Starter plan; JIT provisioning from Business; SCIM on Enterprise.

## What is covered

- Single sign-on through Azure AD, Google Workspace (OAuth), or SAML (Okta, Auth0, generic)
- Just-in-time (JIT) provisioning: organization membership created at first sign-in for allowed email domains
- SCIM provisioning: user creation and management from your identity provider

## Prerequisites

- Admin access to Workload and to your identity provider
- For SAML: the provider's metadata file, or its entity ID, SSO URL, and certificate
- For OAuth: a client ID and client secret created at Azure or Google
- For JIT: at least one allowed email domain

## Step-by-step setup

1. Open Settings > SSO in Workload and choose your provider.
2. OAuth (Azure AD, Google): create the application at the provider, add the redirect URL shown by Workload, then paste the client ID and secret.
3. SAML (Okta, Auth0, generic): download Workload's metadata to configure your provider, then import the provider's metadata or enter entity ID, SSO URL, and certificate.
4. Validate the certificate, save, then enable SSO.
5. Optional: enable JIT provisioning and enter the allowed email domains.
6. Optional (Enterprise): create a SCIM token and enter it in your identity provider to provision users.

## Good to know

- JIT provisioning requires at least one allowed email domain.
- SCIM provisioning is reserved for the Enterprise plan.
- Test SSO sign-in with a test account before enforcing it across the organization.

## Frequently asked questions

### Which identity providers are supported?

Azure AD and Google Workspace through OAuth; Okta, Auth0, and any generic SAML provider through SAML.

### Do I need a specific plan?

SSO/SAML is available from the Starter plan. Just-in-time (JIT) provisioning needs the Business plan and SCIM provisioning the Enterprise plan.

### How do I configure my SAML provider?

Download Workload's metadata file from the SSO page and import it at your provider, then import the provider's metadata into Workload.

### What is JIT?

Just-in-time provisioning automatically creates organization membership at first SSO sign-in, if the email domain is allowed.

## Sitemap

- [Markdown sitemap](https://www.simpleworkload.com/sitemap.md)
- [XML sitemap](https://www.simpleworkload.com/sitemap.xml)
- [llms.txt](https://www.simpleworkload.com/llms.txt)
- [llms-full.txt](https://www.simpleworkload.com/llms-full.txt)
