Back to all guides

    Single Sign-On (SSO) Setup

    Enable SSO for seamless authentication.

    Overview

    Single Sign-On allows users to access Bleach using your organisation's identity provider. This improves security and user experience.

    Supported Providers

    • Microsoft Entra ID (Azure AD)
    • Google Workspace
    • Okta
    • OneLogin
    • Any SAML 2.0 compatible provider

    Step 1: Access SSO Settings

    1. Navigate to Settings → Security → Single Sign-On
    2. Click "Configure SSO"
    3. Select your identity provider

    Step 2: Configure Identity Provider

    In your IdP admin console:

    1. Create a new SAML application for Bleach
    2. Enter the Bleach ACS URL (provided in settings)
    3. Enter the Entity ID (provided in settings)
    4. Configure attribute mappings (email, name)
    5. Download the IdP metadata file

    Step 3: Complete Bleach Configuration

    1. Upload the IdP metadata file or enter details manually
    2. Map IdP attributes to Bleach fields
    3. Configure default role for new SSO users
    4. Save configuration

    Step 4: Test SSO

    1. Click "Test SSO Connection"
    2. Complete authentication with your IdP
    3. Verify successful login
    4. Check that user attributes are mapped correctly

    Step 5: Enable for Users

    1. Enable SSO for your organisation
    2. Choose enforcement (optional or required)
    3. Configure bypass for emergency access
    4. Communicate changes to users

    Troubleshooting

    • Verify certificate hasn't expired
    • Check attribute mapping configuration
    • Ensure email domain matches your organisation
    • Review IdP audit logs for errors

    Need more help?

    Our support team is here to assist you with any questions.

    Contact Support