About SSO
supports SSO via SAML 2.0 and OpenID Connect (OIDC), letting your organization manage access through your existing identity provider (IdP). Common IdPs include Okta, Microsoft Entra ID (formerly Azure AD), OneLogin, Ping Identity, and Google Workspace.Users can also sign in with Google or GitHub without any additional setup. This page covers SSO setup via SAML 2.0 and OIDC only.
Availability
SSO via SAML 2.0 and OIDC is available on the Enterprise plan.What to Know Before Enabling SSO
SSO Replaces Existing Login Methods
Once SSO is enabled for your organization, it becomes the only way users can log in to . Users will no longer be able to sign in with a password, Google, or GitHub. This is by design; it ensures that all user access is managed through your IdP, so your organization’s security policies are consistently enforced. To avoid disruption, communicate this change to all users in your organization before enabling SSO.User Access and JIT Provisioning
Your IT department controls who can access through your IdP by managing user groups. Having a company email address does not automatically grant access. Users must be included in the group configured for in your IdP. When setting up SSO, let the team know which option you prefer for adding users to your organization:- By invitation: Only users who have been invited to your organization can log in, even after SSO is enabled. For information about manually inviting users, see Organizations & Members.
- Just-in-Time (JIT) provisioning: Any user in your IdP’s user group who successfully authenticates via SSO is automatically added to your organization the first time they log in, with no invitation required.
Enable SSO
SSO setup involves multiple steps and ongoing coordination between your team and the team. Here is an overview of the process:- Request SSO through your Organization Settings.
- The team reaches out to begin the process.
- Share the required information with the team: SAML 2.0 or OIDC.
- The team enters your information in the backend.
- The team shares configuration details with you. Add these to your IdP.
- Test that SSO is working correctly.
Request SSO
To request SSO:- Log in to https://ade.landing.ai/.
- Go to the Organization Settings page (to navigate there manually, click your profile icon at the bottom left corner of the page and click Organization Settings).
- In the Single Sign-On (SSO) box, click Contact Support. This sends an automated message to the team. The team will contact you about next steps for setting up SSO.
Required Information for SAML 2.0
Share the following information with the team. Most of it can be found in your IdP’s SAML configuration page. The examples below are for Microsoft Entra ID. Formats and field names vary by IdP.Required Information for OIDC
Share the following information with the team. Most of it can be found in your IdP’s OIDC configuration page. The examples below are for Microsoft Entra ID. Formats and field names vary by IdP.Complete Setup in Your IdP
After the team enters your information in the backend, they will continue coordinating with you to complete the setup. The team will give you the following information to enter in your IdP configuration page:Test That SSO Is Working Correctly
After adding the information from the team, test that SSO is working correctly:- Go to https://login.landing.ai/sign-in.
- If you are currently logged in, log out.
- Click Continue with Enterprise SSO and follow the on-screen prompts to log in. If you’re unable to log in, send an email to support@landing.ai.
View Your SSO Settings
After SSO has successfully been configured, you can view your SSO settings in read-only mode in :- Log in to https://ade.landing.ai/.
- Go to the Organization Settings page (to navigate there manually, click your profile icon at the bottom left corner of the page and click Organization Settings).
- In the Single Sign-On (SSO) box, click View Details. The SSO settings display.