ImmPilotImmPilot
All docs
Security & Compliance

Single sign-on (SSO) setup

Configure SAML SSO with your identity provider on the Enterprise plan.

Enterprise workspaces can require all users to authenticate through the firm's identity provider using SAML 2.0. Supported providers include Okta, Azure AD (Entra ID), Google Workspace, JumpCloud, and any SAML 2.0-compliant IdP.

1. Enable SSO

From Settings → Security → SSO, enable SAML SSO. You will be shown the ImmPilot service provider metadata (entity ID, ACS URL, certificate).

2. Configure your IdP

In your identity provider, create a new SAML application using the metadata above. Configure the attribute mapping: email (required), first name, last name, and optional role.

3. Upload IdP metadata

Return to ImmPilot, upload your IdP's metadata XML, and test the connection with a designated admin account.

4. Enforce for the workspace

Once tested, enable enforcement. Existing users are automatically transitioned to SSO on their next sign-in. Local password authentication can be preserved for a designated break-glass admin account.