Single Sign-On

How to add an SSO provider from Settings → Organization.

Single Sign-On

Single Sign-On lives under Account on Settings → Organization. SSO is configured here — not on Integrations.

Praetorian operators are view-only: they cannot add, rotate, or remove a customer's SSO provider.

Add a provider

  1. Open Settings → Organization.
  2. Select Add Provider.
  3. Add a TXT record on the domain. Guard shows chariot= plus this account's SSO id (not the email address).
  4. Fill Add SSO Provider and select Integrate.
FieldRequiredNotes
DomainYese.g. acme.com
Client IDYes
SecretYesPassword field
Issuer URLYesPlaceholder is a Microsoft Entra issuer
Default Role for SSO UsersYesShown only when RBAC is enabled
Role Claim NameNoShown only when RBAC is enabled (e.g. app_role)

The modal links Okta and Azure how-tos. Ping and domain-verification steps are separate articles in this collection.

After a provider exists

Each connected provider is a card titled SSO: {domain}. Customers can Edit, Rotate Credentials, or Remove.

Require SSO Authentication appears once at least one provider exists. When on: When enabled, users can only authenticate via SSO. Enabling asks Enable SSO-Only Login? If you are not already signed in via SSO, Guard logs you out after save.