> ## Documentation Index
> Fetch the complete documentation index at: https://docs.navattic.com/llms.txt
> Use this file to discover all available pages before exploring further.

# SSO

> Require members to authenticate using an identity provider, such as Okta.

<Info>Enabled in workspaces on the Growth plan and above.</Info>

## Enable SSO for your workspace

Navattic partners with [WorkOS](https://workos.com/) to support all major SSO providers. After it is enabled, you can navigate to Settings > Security to set up the configuration. The configuration setup steps will occur within your selected SSO provider; corresponding provider documentation is linked below.

Click "Manage SSO" to access a WorkOS portal that will walk you through step by step how to configure your chosen provider. Once you have selected your provider and completed the configuration steps, SSO will be turned on for your Navattic workspace, and all users will be required to complete the new authentication flow upon login.

### Supported SSO providers

Click on a provider to be taken to the relevant setup steps in the WorkOS docs. The configuration steps and confirmation will differ for each provider and be covered in the relevant docs.

<CardGroup cols={2}>
  <Card
    horizontal
    title="AD FS SAML"
    href="https://workos.com/docs/integrations/microsoft-ad-fs-saml"
    icon={
  <img
    src="https://cdn.workos.com/provider-icons/light/microsoft.svg"
    className="my-0 h-6 w-6"
  />
}
  />

  <Card
    horizontal
    title="ADP OIDC"
    href="https://workos.com/docs/integrations/adp-oidc"
    icon={
  <img src="https://cdn.workos.com/provider-icons/light/adp.svg" className="my-0 h-6 w-6" />
}
  />

  <Card
    horizontal
    title="Auth0 SAML"
    href="https://workos.com/docs/integrations/auth0-saml"
    icon={
  <img src="https://cdn.workos.com/provider-icons/light/auth0.svg" className="my-0 h-6 w-6" />
}
  />

  <Card
    horizontal
    title="Azure AD SAML"
    href="https://workos.com/docs/integrations/azure-ad-saml"
    icon={
  <img src="https://cdn.workos.com/provider-icons/light/azure.svg" className="my-0 h-6 w-6" />
}
  />

  <Card
    horizontal
    title="CAS SAML"
    href="https://workos.com/docs/integrations/cas-saml"
    icon={
  <img src="https://cdn.workos.com/provider-icons/light/cas.svg" className="my-0 h-6 w-6" />
}
  />

  <Card
    horizontal
    title="ClassLink SAML"
    href="https://workos.com/docs/integrations/classlink-saml"
    icon={
  <img
    src="https://cdn.workos.com/provider-icons/light/classlink.svg"
    className="my-0 h-6 w-6"
  />
}
  />

  <Card
    horizontal
    title="Cloudflare SAML"
    href="https://workos.com/docs/integrations/cloudflare-saml"
    icon={
  <img
    src="https://cdn.workos.com/provider-icons/light/cloudflare.svg"
    className="my-0 h-6 w-6"
  />
}
  />

  <Card
    horizontal
    title="CyberArk SAML"
    href="https://workos.com/docs/integrations/cyberark-saml"
    icon={
  <img
    src="https://cdn.workos.com/provider-icons/light/cyberark.svg"
    className="my-0 h-6 w-6"
  />
}
  />

  <Card
    horizontal
    title="Duo SAML"
    href="https://workos.com/docs/integrations/duo-saml"
    icon={
  <img src="https://cdn.workos.com/provider-icons/light/duo.svg" className="my-0 h-6 w-6" />
}
  />

  <Card horizontal title="Generic SAML" href="https://workos.com/docs/integrations/generic-saml" icon="id-card" />

  <Card
    horizontal
    title="Google OAuth"
    href="https://workos.com/docs/integrations/g-suite-oauth"
    icon={
  <img src="https://cdn.workos.com/provider-icons/light/google.svg" className="my-0 h-6 w-6" />
}
  />

  <Card
    horizontal
    title="Google SAML"
    href="https://workos.com/docs/integrations/google-saml"
    icon={
  <img src="https://cdn.workos.com/provider-icons/light/google.svg" className="my-0 h-6 w-6" />
}
  />

  <Card
    horizontal
    title="JumpCloud SAML"
    href="https://workos.com/docs/integrations/jumpcloud-saml"
    icon={
  <img
    src="https://cdn.workos.com/provider-icons/light/jumpcloud.svg"
    className="my-0 h-6 w-6"
  />
}
  />

  <Card
    horizontal
    title="Keycloak SAML"
    href="https://workos.com/docs/integrations/keycloak-saml"
    icon={
  <img
    src="https://cdn.workos.com/provider-icons/light/keycloak.svg"
    className="my-0 h-6 w-6"
  />
}
  />

  <Card
    horizontal
    title="Microsoft OAuth"
    href="https://workos.com/docs/integrations/microsoft-oauth"
    icon={
  <img
    src="https://cdn.workos.com/provider-icons/light/microsoft.svg"
    className="my-0 h-6 w-6"
  />
}
  />

  <Card
    horizontal
    title="miniOrange SAML"
    href="https://workos.com/docs/integrations/mini-orange-saml"
    icon={
  <img
    src="https://cdn.workos.com/provider-icons/light/miniorange.svg"
    className="my-0 h-6 w-6"
  />
}
  />

  <Card
    horizontal
    title="Okta SAML"
    href="https://workos.com/docs/integrations/okta-saml"
    icon={
  <img src="https://cdn.workos.com/provider-icons/light/okta.svg" className="my-0 h-6 w-6" />
}
  />

  <Card
    horizontal
    title="OneLogin SAML"
    href="https://workos.com/docs/integrations/onelogin-saml"
    icon={
  <img
    src="https://cdn.workos.com/provider-icons/light/onelogin.svg"
    className="my-0 h-6 w-6"
  />
}
  />

  <Card horizontal title="OpenID Connect" href="https://workos.com/docs/integrations/oidc" icon="id-card" />

  <Card
    horizontal
    title="Oracle SAML"
    href="https://workos.com/docs/integrations/oracle-saml"
    icon={
  <img src="https://cdn.workos.com/provider-icons/light/oracle.svg" className="my-0 h-6 w-6" />
}
  />

  <Card
    horizontal
    title="PingFederate SAML"
    href="https://workos.com/docs/integrations/ping-federate-saml"
    icon={
  <img
    src="https://cdn.workos.com/provider-icons/light/ping-identity.svg"
    className="my-0 h-6 w-6"
  />
}
  />

  <Card
    horizontal
    title="PingOne SAML"
    href="https://workos.com/docs/integrations/ping-one-saml"
    icon={
  <img
    src="https://cdn.workos.com/provider-icons/light/ping-identity.svg"
    className="my-0 h-6 w-6"
  />
}
  />

  <Card
    horizontal
    title="Salesforce SAML"
    href="https://workos.com/docs/integrations/salesforce-saml"
    icon={
  <img
    src="https://cdn.workos.com/provider-icons/light/salesforce.svg"
    className="my-0 h-6 w-6"
  />
}
  />

  <Card
    horizontal
    title="Shibboleth"
    href="https://workos.com/docs/integrations/shibboleth"
    icon={
  <img
    src="https://cdn.workos.com/provider-icons/light/shibboleth.svg"
    className="my-0 h-6 w-6"
  />
}
  />

  <Card
    horizontal
    title="SimpleSAMLphp"
    href="https://workos.com/docs/integrations/simple-saml-php-saml"
    icon={
  <img
    src="https://cdn.workos.com/provider-icons/light/simple-saml-php.svg"
    className="my-0 h-6 w-6"
  />
}
  />

  <Card
    horizontal
    title="VMWare SAML"
    href="https://workos.com/docs/integrations/vmware-saml"
    icon={
  <img src="https://cdn.workos.com/provider-icons/light/vmware.svg" className="my-0 h-6 w-6" />
}
  />
</CardGroup>

### FAQs

<AccordionGroup>
  <Accordion title="How do I know the connection is complete?">
    The configuration steps and confirmation will be different for each provider and covered in the
    relevant docs. Once configured, users that exist in both your SSO provider and Navattic
    workspace will be able to sign into your workspace directly from the SSO provider's portal.
  </Accordion>

  <Accordion title="Are all Navattic workspace members required to use SSO, once configured?">
    Yes. If SSO is connected for your workspace, all members of your Navattic workspace regardless
    of user role will be required to login via the SSO provider portal.
  </Accordion>

  <Accordion title="Can I support multiple domains in my SSO provider?">
    Contact [success@navattic.com](mailto:success@navattic.com) to request this service. This is a custom connection that our team
    can help enable.
  </Accordion>
</AccordionGroup>
