Manage Single Sign-On
Last updated: July 29, 2026
You can configure Single Sign-On (SSO) for your organization to enable secure and streamlined user authentication.
Manage Single Sign-On Providers
- In the left navigation panel, locate the ADVANCED section and click Single Sign-On. This navigates you to the dedicated page for managing your organization's SSO settings.
- The Single Sign-On Providers page appears, listing all configured SSO providers. From this page, you can view their status (active/inactive) and whether SSO is enforced.
- If no SSO providers are currently set up, you will see a status message: "No SSO providers configured. Add a provider to enable SSO for your organization."
- To add a new SSO provider, click the + Add Provider button.
- Follow the prompts to provide basic information for your new SSO provider (e.g., provider name, type).
- Once created, you will be redirected to the SSO Provider Detail Page where you can configure advanced settings, manage its lifecycle, and verify domain ownership.
Configuring SAML 2.0 on the Provider Detail Page
When configuring a SAML 2.0 Identity Provider (IdP) on its detail page, follow these steps:
- You will be prompted to provide your IdP metadata. You can do this by either:
- Uploading an XML file: Browse and select the XML metadata file provided by your IdP.
- Providing a URL: Enter the URL where your IdP's metadata XML can be accessed.
- Once the metadata is provided, Installer.com will automatically generate the Assertion Consumer Service (ACS) URL and Entity ID for your organization.
- Copy these generated ACS URL and Entity ID values and configure them in your Identity Provider's settings. These values are crucial for Installer.com to communicate correctly with your IdP.
- Complete any remaining configuration steps as prompted.
SSO Provider Lifecycle Management
On the SSO Provider Detail Page, you can manage the operational status and enforcement of your SSO provider.
- Activate/Deactivate Provider: Use the toggle to activate or deactivate an SSO provider. An inactive provider cannot be used for authentication.
- Enforce SSO: Enable this option to require all users from your organization to log in via this specific SSO provider. This setting is only available after domain ownership has been verified.
- Test SSO Configuration: After configuring your SSO provider, click the "Test Configuration" button to perform a test login. This helps ensure that your setup is correct and users can authenticate successfully.
Domain Ownership Verification
To enforce SSO for your organization, you must first verify ownership of your domain(s). This ensures that only authorized organizations can enforce SSO for a given domain.
- On the SSO Provider Detail Page, navigate to the "Domain Verification" section.
- Enter the domain(s) you wish to verify and click "Request Verification".
- You will be provided with a unique TXT record. Add this TXT record to your domain's DNS settings.
- Once the DNS record has been published, click "Verify Domain". Installer.com will check for the presence of the TXT record. Upon successful verification, you will be able to enforce SSO for that domain.
Need help? Contact Installer.com support.