What is SSO/SAML authentication in Workload?

Workload supports enterprise SSO/SAML with Azure AD, Google Workspace, and Okta. Business+ adds JIT membership for allow-listed email domains. Enterprise adds SCIM 2.0 Users (create/list/patch active soft-disable). Nested SCIM Groups and a single holding IdP are not in scope yet.

Enterprise SSO/SAML Authentication

Centralize access management with Azure AD, Google Workspace, or Okta. Enhanced security, simplified user management, and enterprise compliance.

Why choose SSO/SAML?

Enhanced Security

Centralized authentication with MFA support through your existing identity provider

Simplified Management

JIT membership on first SSO login (allow-listed domains); SCIM Users soft-disable on Enterprise

Enterprise Compliance

Meet security policies and audit requirements with centralized authentication

Better User Experience

Users log in with familiar corporate credentials, no separate passwords

JIT & SCIM — what is actually shipped

Honest IAM scope for RSSI / IdP teams

SSO + JIT (Business+)

First SSO login can create organization membership when the email domain is allow-listed. Default role is configurable.

SCIM Users (Enterprise)

Bearer-token SCIM 2.0 at /api/scim/v2 — create, list, and patch active (soft-disable via disabledAt). Token shown once.

Not yet

SCIM Groups / nested AD sync, automatic hard-delete, and a single IdP for the entire holding remain roadmap — not claimed as live.

Supported Identity Providers

Integrate with your existing enterprise identity infrastructure

Azure AD

Microsoft Azure Active Directory integration with SAML 2.0

Google Workspace

Google Workspace SSO with SAML authentication

Okta

Okta identity provider with SAML 2.0 support

SSO vs Regular Authentication

Security
MFA support, centralized policies
Password-based only
User Management
JIT + optional SCIM Users (Enterprise)
Manual user creation
Compliance
Enterprise audit trails
Limited audit capabilities
User Experience
Single corporate login
Separate password required

Frequently Asked Questions

What is SSO/SAML authentication in Workload?

Workload SSO/SAML lets IT Directors configure enterprise single sign-on with Azure AD, Google Workspace, or Okta. Users sign in with corporate credentials. Business+ can enable JIT membership for allow-listed email domains. Enterprise can enable SCIM 2.0 Users for create/list/patch active (soft-disable). Nested SCIM Groups are not supported yet. Configuration is per organization.

Which identity providers are supported?

Workload supports three major enterprise identity providers: Microsoft Azure AD (Active Directory), Google Workspace (formerly G Suite), and Okta. Each provider is configured per organization, allowing you to use your existing corporate identity infrastructure. The configuration process is straightforward and includes metadata exchange, certificate management, and attribute mapping. Once configured, users can authenticate using their corporate credentials, and Workload automatically maps user attributes to roles and permissions within the platform.

How does SSO improve security?

SSO/SAML improves security by centralizing authentication through your IdP (typically with MFA), removing separate app passwords, and concentrating access control. On Enterprise, SCIM can soft-disable members when the IdP marks them inactive. Hard-delete and nested group sync are not claimed. Audit trails remain available for administrators.

Can I use SSO alongside regular authentication?

Yes, Workload supports both SSO/SAML authentication and regular email/password authentication. Organizations can choose to use SSO exclusively, allow both methods, or use regular authentication as a fallback. This flexibility is important for organizations that are transitioning to SSO or have users who may not have SSO access. When SSO is configured, it becomes the primary authentication method, but regular authentication remains available as a backup option. This ensures that users can always access Workload, even if there are temporary issues with the identity provider.

How do I configure SSO for my organization?

Configuring SSO for your organization in Workload is a straightforward process that typically takes 15-30 minutes. First, you need to access the SSO settings in your organization's dashboard (available for Business and Enterprise plans). Then, you'll need to obtain the SAML metadata from your identity provider (Azure AD, Google Workspace, or Okta) and provide it to Workload. Workload will generate its own SAML metadata that you'll need to configure in your identity provider. Once both sides are configured, you can test the SSO connection and enable it for your organization. The system includes step-by-step guides for each identity provider, making the configuration process simple even for non-technical users. Workload's support team is also available to assist with SSO configuration if needed.

What are the benefits of SSO for IT Directors?

SSO helps IT Directors with centralized auth and MFA via the corporate IdP, fewer password resets, and clearer access control. JIT reduces invite friction for allow-listed domains; SCIM Users (Enterprise) supports IdP-driven soft-disable. Pair with the Trust Center diligence pack for procurement reviews. Signed DPA/SLA remain Legal deliverables.

Ready to secure your IT infrastructure?

Configure SSO/SAML authentication for your organization in 15-30 minutes