Single Sign-On

Settings → Organization: connect your identity provider for single sign-on and require SSO for every sign-in.

Single Sign-On is in the Account section of Settings → Organization. You configure SSO here, not on the Integrations page.

Praetorian staff can view your SSO providers but cannot add, rotate, or remove them.

Add a provider

  1. Open Settings → Organization.
  2. Select Add Provider.
  3. Add the TXT record shown in the dialog to your domain. Its value is chariot= followed by your account's verification ID. See SSO Domain Verification.
  4. Fill Add SSO Provider and select Integrate.

Field

Required

Notes

Domain

Yes

e.g. acme.com

Client ID

Yes

Secret

Yes

Password field

Issuer URL

Yes

Placeholder is a Microsoft Entra issuer

Default Role for SSO Users

Yes

Shown only when role-based access is enabled

Role Claim Name (Optional)

No

Shown only when role-based access is enabled

Without role-based access, every SSO user is given the Admin role.

The dialog links to the Okta and Azure guides. Provider guides: Okta, Azure, PingID.

After a provider exists

Each connected provider is a card titled SSO: {domain}. Customers can Edit, Rotate Credentials, or Remove. Removing asks for confirmation.

Require SSO Authentication appears once at least one provider exists. When on: When enabled, users can only authenticate via SSO. Enabling asks Enable SSO-Only Login? If you are not signed in through SSO when you enable it, Guard signs you out so you can sign back in with SSO. Guard shows SSO-only login enabled. Logging out... first. If you are already signed in through SSO, Guard shows SSO-only login enabled. Password authentication is now blocked for non-SSO accounts. Turning it off shows SSO-only login disabled. Password authentication is now allowed.