Back to all guides
Single Sign-On (SSO) Setup
Enable SSO for seamless authentication.
Overview
Single Sign-On allows users to access Bleach using your organisation's identity provider. This improves security and user experience.
Supported Providers
- Microsoft Entra ID (Azure AD)
- Google Workspace
- Okta
- OneLogin
- Any SAML 2.0 compatible provider
Step 1: Access SSO Settings
- Navigate to Settings → Security → Single Sign-On
- Click "Configure SSO"
- Select your identity provider
Step 2: Configure Identity Provider
In your IdP admin console:
- Create a new SAML application for Bleach
- Enter the Bleach ACS URL (provided in settings)
- Enter the Entity ID (provided in settings)
- Configure attribute mappings (email, name)
- Download the IdP metadata file
Step 3: Complete Bleach Configuration
- Upload the IdP metadata file or enter details manually
- Map IdP attributes to Bleach fields
- Configure default role for new SSO users
- Save configuration
Step 4: Test SSO
- Click "Test SSO Connection"
- Complete authentication with your IdP
- Verify successful login
- Check that user attributes are mapped correctly
Step 5: Enable for Users
- Enable SSO for your organisation
- Choose enforcement (optional or required)
- Configure bypass for emergency access
- Communicate changes to users
Troubleshooting
- Verify certificate hasn't expired
- Check attribute mapping configuration
- Ensure email domain matches your organisation
- Review IdP audit logs for errors