Single Sign-On
Settings → Organization: connect your identity provider for single sign-on and require SSO for every sign-in.
Single Sign-On is in the Account section of Settings → Organization. You configure SSO here, not on the Integrations page.
Praetorian staff can view your SSO providers but cannot add, rotate, or remove them.
Add a provider
- Open Settings → Organization.
- Select Add Provider.
- Add the TXT record shown in the dialog to your domain. Its value is
chariot=followed by your account's verification ID. See SSO Domain Verification. - Fill Add SSO Provider and select Integrate.
Without role-based access, every SSO user is given the Admin role.
The dialog links to the Okta and Azure guides. Provider guides: Okta, Azure, PingID.
After a provider exists
Each connected provider is a card titled SSO: {domain}. Customers can Edit, Rotate Credentials, or Remove. Removing asks for confirmation.
Require SSO Authentication appears once at least one provider exists. When on: When enabled, users can only authenticate via SSO. Enabling asks Enable SSO-Only Login? If you are not signed in through SSO when you enable it, Guard signs you out so you can sign back in with SSO. Guard shows SSO-only login enabled. Logging out... first. If you are already signed in through SSO, Guard shows SSO-only login enabled. Password authentication is now blocked for non-SSO accounts. Turning it off shows SSO-only login disabled. Password authentication is now allowed.