Single sign-on (SSO) setup
Configure SAML SSO with your identity provider on the Enterprise plan.
Enterprise workspaces can require all users to authenticate through the firm's identity provider using SAML 2.0. Supported providers include Okta, Azure AD (Entra ID), Google Workspace, JumpCloud, and any SAML 2.0-compliant IdP.
1. Enable SSO
From Settings → Security → SSO, enable SAML SSO. You will be shown the ImmPilot service provider metadata (entity ID, ACS URL, certificate).
2. Configure your IdP
In your identity provider, create a new SAML application using the metadata above. Configure the attribute mapping: email (required), first name, last name, and optional role.
3. Upload IdP metadata
Return to ImmPilot, upload your IdP's metadata XML, and test the connection with a designated admin account.
4. Enforce for the workspace
Once tested, enable enforcement. Existing users are automatically transitioned to SSO on their next sign-in. Local password authentication can be preserved for a designated break-glass admin account.