Single sign-on (SSO) lets your team log in to Community with the company credentials they already use, through an identity provider such as Okta, Microsoft Entra ID or OneLogin. The Community team sets it up for you: your IT team gathers a few details from your identity provider, you send them to us, and we confirm when SSO is ready.
Who this applies to: Leaders on the Advanced, Professional, Premier or Ultimate plan whose company uses a SAML identity provider. Setup needs someone from your IT team. To check your plan, contact your Account Executive or Support. SSO is for your team's dashboard logins, not for Members.
What is Single Sign-On (SSO)
SSO connects Community to your company's identity provider (IdP), so your team logs in with their work account instead of a separate Community password.
There are two ways to log in once SSO is set up:
| Login method | Where it starts | What happens |
|---|---|---|
| IdP-initiated | Your company's SSO dashboard | You click the Community tile and are logged in. |
| SP-initiated | The Community login page | You click Sign in with SSO, enter your work email, and finish signing in on your company's login page. |
Both methods work for every user once SSO is configured. If someone opens a link to a specific page in Community, such as a campaign or a message, they land on that page after logging in.
SSO in Community works this way today:
- SSO is optional. Your team can still log in with a Community username and password.
- Setup is done by Community. Our Support and Services teams configure SSO. You cannot set it up or change it yourself in the dashboard.
- SSO cannot be enforced. There is no setting that makes SSO the only way to log in.
Why should I use SSO?
Your team logs in with the account your company already manages, so there is one less password to create, remember and reset. Access runs through the same identity provider your IT team uses for other tools, which keeps sign-in for Community consistent with the rest of your company's software.
Because password login stays available, SSO does not replace your own process for removing someone's access to Community.
How do I use it?
Setting up SSO for your organization
- Confirm your account is on the Advanced, Professional, Premier or Ultimate plan. If you're not sure, ask your Account Executive or Support.
- Ask your IT team to set up Community as an application in your identity provider.
- Have your IT team collect the metadata details below.
- Send the details to your Community contact, or open a ticket with Submit a request.
- Wait for the Community team to confirm that SSO is configured.
Single Sign-On Metadata
| Detail | What it is |
|---|---|
| Entity ID | The unique identifier for the Community application |
| ACS URL | The address your identity provider sends login responses to |
| Public X.509 certificate | Used to verify the SAML responses from your identity provider |
| Email domains | The email domains whose users should be routed through SSO |
Only users whose email address is on one of the domains you list are routed through SSO.
Testing SSO
Test with a few users before you tell the whole team.
- Have a test user log in from your company's SSO dashboard, as described in Logging in from your company's SSO dashboard.
- Have the same user log out, then log in from the Community login page, as described in Logging in from the Community login page.
- Open a link to a specific page in Community, such as a campaign, while logged out. Log in with SSO and check that you land on that page.
- If any of these fail, see Why can't my team log in with SSO? under Common questions.
Logging in from your company's SSO dashboard
- Open your company's SSO dashboard, such as Okta or Entra.
- Click the Community tile.
You are logged in to Community without entering a password.
Logging in from the Community login page
- Go to the Community login page.
- Click Sign in with SSO.
- Enter your work email address.
- Sign in on your company's login page.
You are returned to Community and logged in.
Common questions
Why can't my team log in with SSO?
The most likely cause is a configuration mismatch between your identity provider and Community.
| Cause | How to tell | Fix |
|---|---|---|
| The user's email domain isn't set up for SSO | The user gets an SSO login failure on the Community login page. | Check that the domain is on the list you sent us. To add one, open a ticket with Submit a request. |
| Your identity provider's settings don't exactly match Community's ACS URL and Entity ID | TK | Have your IT team compare the settings character by character. See Setting up SSO for your organization. |
| Something else | The two checks above look correct | Open a ticket. The Community team can review the SAML logs to find the problem. |
Can users still log in with a username and password?
Yes. SSO is optional, and username and password login keeps working for everyone.
Can we enforce SSO for all users?
Not at the moment. There is no setting to make SSO the only way to log in to Community.
Can we manage SSO settings ourselves?
No. The Community team handles all SSO configuration. To make a change, such as adding an email domain, contact your Community contact or open a ticket with Submit a request.
What if a user has multiple Community accounts?
After logging in with SSO, they're asked to choose which account to open.