---
title: "SSO and Directory Sync"
description: "Enterprise organizations on the Enterprise plan can configure SAML Single Sign-On (SSO) and SCIM Directory Sync to streamline team access and management. SAML SSO allows your team members to log in..."
last_updated: "2026-10-05T05:09:52.159003+00:00"
canonical_url: "https://www.doc0.dev/docs/934e554a-e6a1-476f-bb2f-23e62d86c3fd/guide/integrations/sso-and-directory-sync"
---

## Overview

Enterprise organizations on the **Enterprise plan** can configure **SAML Single Sign-On (SSO)** and **SCIM Directory Sync** to streamline team access and management. SAML SSO allows your team members to log in using your organization’s identity provider, while SCIM Directory Sync automatically provisions and deprovisions user accounts based on your directory settings.

> [!IMPORTANT]
> Both SAML SSO and SCIM Directory Sync require an **Enterprise plan** and appropriate workspace permissions (`workspaces.write`).

---

## Supported Identity Providers

The following identity providers are fully supported for both SAML SSO and SCIM user provisioning:

| Provider Name | SAML Identifier | SCIM Identifier | Configuration Input Type |
| :--- | :--- | :--- | :--- |
| Okta | `okta` | `okta-scim-v2` | Metadata URL |
| Entra ID (formerly Azure AD) | `azure` | `azure-scim-v2` | App Federation Metadata URL |
| Google | `google` | `google` | XML Metadata File |

> [!NOTE]
> Supported providers: `Okta`, `Entra ID (formerly Azure AD)`, `Google`.

---

## Configuring SAML Single Sign-On

### Overview

Setting up SAML SSO allows members of your organization to authenticate securely using your identity provider. 

- An active **Enterprise** plan workspace.
- You must be logged into your account using your organization’s official work email address (generic email domains are not permitted for SAML setup).
- Administrative access to your identity provider to retrieve metadata.

### Step-by-Step Configuration

1. Navigate to your workspace **Settings**, then select **Security**.
2. Under the **SAML Single Sign-On** section, click **Configure** to open the setup modal.
3. Select your identity provider from the dropdown menu (`Okta`, `Entra ID`, or `Google`).
4. Provide the required metadata:
   - For **Okta** or **Entra ID**, paste your provider's **Metadata URL** or **App Federation Metadata URL**.
   - For **Google**, upload your exported XML metadata file.
5. Click **Save changes** to establish the SAML connection.

```mermaid
flowchart TD
    A[User opens Security Settings] --> B[Clicks Configure SAML]
    B --> C[Selects Provider & Adds Metadata]
    C --> D[Saves Connection]
```

---

## Configuring SCIM Directory Sync

### Overview

Directory Sync using SCIM automatically provisions new users and deprovisions removed or deactivated users from your workspace.

### Step-by-Step Configuration

1. Go to your workspace **Settings**, then select **Security**.
2. Locate the **Directory Sync** section and click **Configure**.
3. Select your directory provider (`Okta`, `Entra ID`, or `Google`).
4. Copy the provided **SCIM 2.0 Base URL** (or Tenant URL) and **OAuth Bearer Token** (or Secret Token) into your identity provider's directory configuration.
5. Save the configuration to activate syncing.

> [!TIP]
> When a user is activated or created in your identity provider, an invitation or workspace membership is automatically generated. When deactivated or deleted, their workspace access is immediately revoked.

---

## Managing and Removing Security Settings

If you need to update or remove your SSO or SCIM configurations, you can do so directly from the **Security** settings page.

> [!CAUTION]
> Removing SAML or SCIM is irreversible and will immediately disconnect your identity provider integration, revoking enforced domain sign-in rules.

To remove a connection:
1. Click the options menu (three dots) next to the configured SAML or SCIM provider.
2. Select **Remove**.
3. Type the required verification phrase (`confirm remove saml` or `confirm remove scim`) to confirm the action.

## Related

- [Setting Up Workspaces](https://www.doc0.dev/docs/934e554a-e6a1-476f-bb2f-23e62d86c3fd/guide/getting-started/setting-up-workspaces)


## Sitemap

See the full [sitemap](https://www.doc0.dev/docs/934e554a-e6a1-476f-bb2f-23e62d86c3fd/llms.txt) for all pages in this wiki.
