Before you start
You need permission to read Security settings and identity providers. You also need permission to configure or remove an application provider. Create an OAuth or OpenID Connect application in your identity provider. Keep its client ID and client secret available.
Open the Single Sign-On tab
1
Open Settings
Click the gear icon () in the top navigation bar.
2
Select Security
Select Security in the Settings sidebar.
3
Select Single Sign-On
The page opens on the Single Sign-On tab. You can also open
/settings/security?tab=sso directly.Register the callback URL
Copy the authorized redirect URI from the Console and add it to the provider application. The Console derives the value from the current browser origin. Confirm that this is the canonical Console URL that your users open. The path ends with:
Configure a provider
1
Open the configuration form
Click Configure SSO. If a provider exists, use the reconfigure action instead.
2
Select the provider type
Select Google, Microsoft Entra ID, Okta, or Custom OpenID Connect.
3
Enter the credentials
Enter the client ID and client secret. You must enter the complete secret on every save or reconfiguration.
4
Enter the provider-specific settings
For Okta, enter the Okta domain. For Custom OpenID Connect, enter the issuer URL and optional scopes.
5
Test the connection
Run the connection test before you save.
6
Review the checks
Fix each failed check. Review the discovered authorization, token, and user-info endpoints.
7
Save the provider
Register the callback URL and resolve every required preflight failure before you save. The Console does not block saving when preflight has not passed.
Provider-specific settings
Google and Microsoft Entra ID
Enter the client ID and client secret from the provider application. Register the callback URL shown by the Console.Okta
Enter the client ID, client secret, and Okta organization domain. Register the callback URL manually in Okta. The Console does not present the callback probe as a reliable Okta check.Custom OpenID Connect
Enter an absolute issuer URL. Access Manager uses OpenID Connect discovery to resolve the authorization, token, and user-info endpoints. Scopes are optional. Enter them as a space-separated list, such asopenid profile email.
Review the active provider
The provider summary shows its type, display name, and masked client ID. The callback URL appears in the configuration form. Custom OpenID Connect endpoints appear during configuration when they apply. The client secret is write-only and never appears after you save it. To change the provider, open the reconfiguration form and enter the full credentials again.
Remove the provider
Removing the provider stops new SSO sign-ins for the tenant. Existing sessions continue until they expire or are revoked through the relevant session controls. When Identity removes an active provider, it enables local password login, even if the previous SSO policy disabled it. Removing SSO when no provider is active leaves the current password policy unchanged.
Test user sign-in
1
Open a private browser session
Use a private session so an existing provider session does not hide the login flow.
2
Enter a tenant email address
Enter an email address whose domain belongs to the configured tenant.
3
Continue with the provider
Select the provider if password login is also available. The Console redirects automatically when SSO is the only method.
4
Complete provider authentication
Sign in at the identity provider and return to the Console callback.
5
Complete MFA if required
Finish the second verification step for users who have MFA enabled.
Related pages
Single sign-on
Provider support, tenant resolution, and password policy.
SSO deployment requirements
Configure the callback and browser-reachable Auth route.

