Single Sign-On

How to add an SSO provider from Settings → Organization.

Single Sign-On

Single Sign-On lives under Account on Settings → Organization. SSO is configured here — not on Integrations.

Praetorian operators are view-only: they cannot add, rotate, or remove a customer's SSO provider.

Add a provider

  1. Open Settings → Organization.
  2. Select Add Provider.
  3. Add a TXT record on the domain. Guard shows chariot= plus this account's SSO id (not the email address).
  4. Fill Add SSO Provider and select Integrate.

Field

Required

Notes

Domain

Yes

e.g. acme.com

Client ID

Yes

Secret

Yes

Password field

Issuer URL

Yes

Placeholder is a Microsoft Entra issuer

Default Role for SSO Users

Yes

Shown only when RBAC is enabled

Role Claim Name

No

Shown only when RBAC is enabled (e.g. app_role)

The modal links How to: Okta SSO Configuration and How to: Azure SSO Configuration. Ping and domain-verification steps are separate articles in this collection.

After a provider exists

Each connected provider is a card titled SSO: {domain}. Customers can Edit, Rotate Credentials, or Remove. Removing asks for confirmation.

Require SSO Authentication appears once at least one provider exists. When on: When enabled, users can only authenticate via SSO. Enabling asks Enable SSO-Only Login? If you are not already signed in via SSO, Guard logs you out after save so password login cannot continue.