Business and Custom plans support SSO so your team signs in through your identity provider.
Supported protocols
- SAML 2.0 — Okta, Microsoft Entra ID, OneLogin, PingFederate, and any standards-compliant IdP.
- OIDC — for IdPs that prefer OpenID Connect.
What SSO gives you
- Sign-in policy (MFA, device trust, network rules) enforced by your IdP, not ours.
- Deprovisioning in your IdP revokes Anysola access on the next session check.
- Optional enforced SSO: members cannot use password sign-in once enabled.
Setup
- Contact us to enable SSO on your workspace.
- Exchange metadata: we provide the SP entity ID and ACS URL; you provide your IdP metadata XML.
- Test with a pilot group, then enable enforcement.
Role mapping from IdP groups to workspace roles is available on the Custom plan.