Enterprise SSO connects a workspace to Microsoft or a custom SAML identity provider. Verify the organization’s domains, provide IdP details or metadata, choose a login method, and optionally enable just-in-time user provisioning.
This is SAML workspace configuration; it does not claim SCIM, SOC 2 certification or audit logs.
Domain verification
DomainOne or more
NonceVerification record
StateVerified / pending
ScopeWorkspace
Verification records belong to the workspace; an email domain alone is not treated as proof.
Establish the domain boundary
SSO Domain Verification
Each workspace can maintain multiple SSO domain-verification records. The verification flow records the domain, nonce and verification state before an organization relies on it for sign-in behavior.
Microsoft and custom provider choices are available.
Domain verification is part of SSO setup, not a global account setting.
Workspace SSO is plan-gated; do not assume a lower tier can create a configuration.
Configure the identity provider
SAML Identity Provider Settings
Set IdP metadata or the SSO URL, entity ID and certificate, then map email, first name, last name and role attributes as needed. Optional JIT provisioning is configured with the SSO record rather than implied by every SAML login.
SAML settings
MetadataXML or fields
IdPSSO URL / entity / cert
AttributesEmail, name, role
LoginEnforce SAML or any method
Configuration supports explicit attributes and a login-method choice; availability is governed by workspace permissions and plan.
Explicit exclusions
SCIMNot advertised
SOC 2Not claimed
Audit logsNot claimed
Role mappingAttribute setting, not entitlement claim
Use workspace role permissions to understand what a provisioned member can do after access is granted.
What this page does not promise
SSO Security Feature Limits
SSO addresses identity-provider sign-in for a workspace. It is not a claim of directory synchronization, security certification, audit-log product, or a universal role policy. Those distinctions matter when procurement asks for controls the application does not expose here.