Single Sign-On (SSO) — One Corporate Login for Every Member
Authenticate SmartSuite through your own identity provider using SAML or OpenID Connect—centralizing login policy, retiring standalone passwords, and keeping access under IT control.
What Is Single Sign-On (SSO)?
Single Sign-On (SSO) is a SmartSuite capability that authenticates workspace Members through an organization's own identity provider instead of SmartSuite-managed passwords, using the SAML and OpenID Connect federation protocols. It helps IT and security teams centralize authentication policy—one corporate credential, one place to grant and revoke access, no separate password to manage. SSO is available on the Enterprise plan and is configured from the Security tab in Workspace Administration.
Federation Protocols
Authenticate With SAML or OpenID Connect
SmartSuite supports the two federation protocols enterprise identity stacks are built on: SAML and OpenID Connect (OIDC). SAML setup takes your IdP's metadata file or URL plus a user email attribute mapping; OIDC takes your email domain, Client ID, Client Secret, and Issuer URL.
If your organization runs a protocol beyond SAML and OIDC, SmartSuite's support team works with you directly on options.
Identity Providers
Connect Microsoft Entra ID, Okta, Google, and More
SmartSuite documents step-by-step configuration for Microsoft Entra ID (Azure AD) and works with the IdPs enterprises already run—customers authenticate through Okta and Google, and institutions using Shibboleth connect over SAML.
Standards-based federation means your existing identity investment carries over: conditional access, MFA, and login policy stay enforced where they already live—in your IdP.
Admin Configuration
Configure SSO From Workspace Administration
An Administrator sets up SSO from the Security tab in Workspace Administration—no professional services engagement required. Enter the IdP details, verify the connection, and Members start signing in with their corporate credentials.
Membership stays governed: Members must still receive an administrator invitation before SSO access is enabled for them, so your IdP authenticates users while SmartSuite admins decide who belongs in the workspace.
Access Continuity
Keep Members Working Through IdP Migrations
Identity infrastructure changes—providers get replaced, tenants get consolidated. If SSO is disabled workspace-wide during a migration, affected Members recover access through the standard password-reset flow and sign in with email and password until the new IdP is live.
A mid-migration cutover never locks your organization out of its work.
Single Sign-On (SSO)
For governed organizations, authentication is policy--not a per-app setting. Single Sign-On puts SmartSuite behind the same identity controls your access-management program already enforces across the stack.
Route all SmartSuite logins through Okta or Microsoft Entra ID so conditional access, device trust, and MFA policies apply to governed registers exactly as they do to every other sanctioned app—one policy to maintain, one to evidence.
Centralized IdP authentication gives compliance teams clean answers for access-control audits: one login policy, one revocation point, and no orphaned SmartSuite passwords to account for.
An organization replacing its identity provider temporarily disables SSO, Members fall back to email and password via the standard reset flow, and SSO is re-enabled once the new IdP is configured—a continuity path you can plan and test like any other resilience exercise.
A university or public-sector body running Shibboleth connects SmartSuite over SAML, so staff authenticate with their institutional identity under existing federation agreements.
Pair Single Sign-On with SCIM Provisioning so the IdP that authenticates Members also creates, updates, and deprovisions their accounts—joiners, movers, and leavers handled without manual work.
For governed organizations, authentication is policy--not a per-app setting. Single Sign-On puts SmartSuite behind the same identity controls your access-management program already enforces across the stack.
Single Sign-On lets your organization authenticate SmartSuite Members through its own identity provider instead of SmartSuite-managed passwords. SmartSuite supports the SAML and OpenID Connect protocols, configured from the Security tab in Workspace Administration.
Any IdP that speaks SAML or OpenID Connect. SmartSuite documents configuration for Microsoft Entra ID (Azure AD), customers run SSO with Okta and Google, and Shibboleth is confirmed compatible via SAML. For other protocols, contact SmartSuite support.
SAML-based Single Sign-On is an Enterprise plan feature. It is also excluded from the free trial, which otherwise runs on Professional-plan features.
No. Members must still be invited by an administrator before SSO access is enabled for them. Your IdP handles authentication; SmartSuite administrators keep control of workspace membership. To automate account creation itself, add SCIM Provisioning.
Members who relied on SSO regain access through the standard "Forgot your password?" flow, setting an email and password login until SSO is re-enabled. That keeps an IdP migration from locking anyone out.
No. SmartSuite also offers social sign-in with Google, Microsoft, and Apple ID on all plans—convenient individual logins. Enterprise SSO is different: workspace-wide SAML or OIDC federation with your organization's own identity provider and policies.
SSO centralizes authentication in a system your auditors already review—your IdP. Login policy, MFA enforcement, and access revocation are governed in one place, which simplifies evidence for access-control requirements in frameworks like SOC 2 and ISO 27001.
Put SmartSuite Behind Your Identity Provider
Configure SAML or OpenID Connect from Workspace Administration—and give every Member one governed corporate login.