SSO & SAML setup

8 min readLast updated 2026-04-20

Configure SAML 2.0 single sign-on with Okta, Azure AD, Google Workspace, or any identity provider.

SSO is available on Enterprise plans. It supports SAML 2.0 with just-in-time provisioning and role mapping from your IdP.

Supported providers

  • Okta
  • Azure Active Directory
  • Google Workspace
  • OneLogin
  • Ping Identity
  • Generic SAML 2.0

Setup steps

  1. 1Go to Settings > Security > SSO
  2. 2Download the Check Studio metadata XML
  3. 3Upload it to your IdP and configure ACS URL
  4. 4Map IdP groups to Check Studio roles (Admin, Editor, Viewer)
  5. 5Enable SSO and test login

JIT provisioning

Users logging in via SSO for the first time are automatically provisioned. Their role is determined by the group mapping you configure.

Enforcement

After SSO is enabled, you can disable password login to enforce SSO-only access. This is recommended for compliance.

Was this article helpful?

Still have questions?

Our support team is here to help. Reach out directly or search the docs.