Settings SSO

Configure enterprise access, verified domains, join policy, and directory sync.

Settings → SSO is where you manage the enterprise identity controls that govern how company users join and access the workspace.

SSO settings showing enterprise status, company-domain controls, join policy settings, and directory sync state. Members workspace showing the roster view impacted by enterprise access and join-policy decisions. Roles settings showing the permission model that often pairs with SSO and JIT access configuration.

Typical Workflow

  1. Open Settings → SSO.
  2. Review current enterprise status.
  3. Set Require SSO, join policy, and JIT default role if needed.
  4. Add and verify company domains.
  5. Review directory sync state and reconcile when necessary.

After setup, employee access follows the organization’s intended identity policy without breaking workspace ownership protections.

What you can configure

  • SSO requirement
  • domain join policy
  • JIT default role
  • company domains
  • directory sync reconciliation
  • SSO portal handoff

State and permission behavior

  • only organization owners can change enterprise access settings
  • directory reconciliation can still skip protected-owner scenarios
  • verified domains and join policy must agree with the company’s real onboarding model

Troubleshooting

Domain users still cannot join the workspace correctly

Check both domain verification state and the selected join policy.

Directory sync looks connected but access is still drifting

Run reconcile and then review any skipped-owner protections or directory errors surfaced in the UI.

We use cookies to improve your experience, analyze traffic, and personalize content.