Documentation menu

SSO

Configure single sign-on for your DataAgent organisation.

DataAgent supports SAML 2.0 and OIDC-based single sign-on. SSO is available on Enterprise plans.

Supported providers

  • Okta
  • Google Workspace
  • Microsoft Entra ID (Azure AD)
  • Any SAML 2.0 or OIDC-compatible identity provider

Setup

SSO is configured by DataAgent support. To enable it for your organisation:

  1. Contact support with your identity provider name
  2. Support will provide the DataAgent SAML metadata or OIDC callback URL
  3. Configure the DataAgent application in your identity provider
  4. Provide support with your IdP metadata URL or OIDC discovery document
  5. Support will complete the configuration and enable SSO for your organisation

Behaviour after SSO is enabled

  • Members sign in via your identity provider instead of email and password
  • Existing members retain their current roles
  • New members provisioned via SSO are assigned the Viewer role by default — an Admin or Owner must upgrade their role after first sign-in
  • Email invitations remain available for members without IdP accounts

Just-in-time provisioning

When SSO is enabled with JIT provisioning, team members who authenticate via your IdP for the first time are automatically added to the organisation as Viewers. No invitation is required.

Contact support to enable JIT provisioning.

Essential Cookies keep the site working and cannot be switched off. Everything else is off until you turn it on.