Single Sign-On
Single Sign-On
Single sign-on is available on the Enterprise plan.
Only organization admins can configure single sign-on.
Single sign-on (SSO) lets members of your organization sign in to GlideOS through your identity provider, using SAML or OIDC. You configure it once for your organization, then enforce it for members on your company’s email domain. SSO changes how members sign in, not what they can access. Invitations and roles still decide who belongs to your organization and what they can do.
Set Up Single Sign-On
Admins can configure SSO in the organization Settings. Have admin access to your identity provider ready before you start.
The checklist tracks four rows: Identity provider connected, Email attribute mapped, Company domain verified, and Connection tested. When a row is complete, it shows a check, and Company domain verified shows the verified domain next to it.
Enforce Single Sign-On
When all four checklist rows are complete, you can enforce SSO for your organization. Enforcement applies by email domain. Members whose email matches a verified domain sign in through your identity provider. Members on other domains, like contractors or guests from another company, keep their existing sign-in method.
Once enforced, the tab shows SSO is enforced for @yourdomain.com.
If a member’s account already uses SSO with a different organization, enforcement stops and tells you which members to resolve before you can continue.
To turn SSO off, click Disable enforcement. Disabling restores email sign-in for members on your domain, and it stays available even if your identity provider configuration breaks, so an admin can always revert an organization back down to regular sign-in.
What Members See at Sign-In
Members on a verified domain enter their work email on the sign-in page and continue to your identity provider. If a member tries a sign-in like Google instead, GlideOS asks them to enter their work email to continue with their identity provider.