EnterpriseConnect your identity provider so teammates sign in with work email. Password login stays available alongside SAML single sign-on.
Who this is for
Enterprise workspaces. Workspace admins configure SSO. IT can use a time-limited setup link without an Elevale login.
Before you start
Enterprise plan with admin access to Workspace Settings.
DNS access to verify your email domain.
SAML metadata from Okta, Microsoft Entra ID, Google Workspace, or another SAML 2.0 provider.
Steps
Open Workspace Settings → General → Security → Single sign-on.
Add your email domain and create the DNS TXT record shown.
Click Verify DNS when the record propagates.
Choose Okta, Microsoft Entra ID, Google Workspace, or Other SAML 2.0.
Copy ACS / Reply URL and Entity ID / Audience into your IdP SAML app.
Paste your IdP Metadata URL or metadata XML.
Click Connect identity provider.
Test with a work email, then toggle SSO on when ready.
Optional: click Create setup link to send a 7-day IT setup link. Revoke links when setup is complete.
What you should see
Members with verified domains can sign in through the identity provider. Password login remains available unless you change policy elsewhere.
Troubleshooting
Verify DNS fails Wait for DNS propagation and confirm the TXT record matches the value shown exactly.
SAML test login errors Check ACS URL, Entity ID, and certificate expiry in your IdP. Re-paste metadata if the IdP rotated keys.
IT setup link expired Create a new setup link from Single sign-on settings and revoke the old one.
Common questions
Does SSO replace password login?
No. Password login stays on unless your organisation chooses a different policy outside this guide.
Can IT configure SSO without an Elevale account?
Yes. Create setup link and share the 7-day URL. Revoke it after configuration.
Where is SCIM provisioning documented?
See Security, MFA, and sessions for SCIM overview links when your contract includes provisioning.