Admin Guide
SSO Configuration (Admin Guide)
Step-by-step admin guide to configuring SSO for your organization.
See SSO & SCIM Configuration for complete technical setup.
Admin Decision Points
| Decision | Options | Recommendation |
|---|---|---|
| SSO Enforcement | Optional vs. Required | Required for Enterprise (eliminates password risk) |
| Local Auth Fallback | Allow email/password alongside SSO | Keep for break-glass admin access only |
| JIT Provisioning | Auto-create accounts on first SSO login | Enable if not using SCIM |
| SCIM | Automatic user lifecycle | Enable for 50+ users |
| Session Lifetime | How long SSO sessions last | Match your IdP session policy |
Break-Glass Access
- Always keep at least 1 admin account with email/password auth
- This account is used if SSO goes down (IdP outage)
- Store credentials securely (e.g., company password manager)
- Test break-glass account quarterly