Platform · Single sign-onEnterprise
Your identity provider, in charge of who gets in.
Connect Stable Baseline to Microsoft Entra ID, Okta, Google Workspace or any SAML 2.0 provider. Your team signs in with the account they already have, and you decide centrally who keeps access.
Single sign-on is an Enterprise feature
Choose your identity provider
Every provider below is supported. The setup steps differ, and so does one detail that matters a great deal later: whether your provider publishes a metadata URL we can keep reading, or only a file you have to send us once.
How it works
Setting up single sign-on has three steps, and they are deliberately separate so nothing changes for your users until you say so.
- Connect your provider. You give us your identity provider’s metadata, either as a URL or as an XML file, and you paste our values into your provider.
- Verify your domain. You add a DNS TXT record to prove you own the email domain. Until a domain is verified, nothing is routed through your provider.
- Turn on enforcement, when you are ready. This is a separate switch, and it is the one that changes how people sign in.
Activating is not the same as enforcing
This distinction catches people out, so it is worth being precise.
| Single sign-on available | Single sign-on enforced | |
|---|---|---|
| What your users see | A “Continue with single sign-on” button, alongside the normal sign-in options | Only the single sign-on button |
| Passwords | Keep working | Removed, and cannot be set again |
| Who it applies to | Anyone on a verified domain | Everyone except organisation owners |
| Reversible by you | Yes, at any time | Yes, at any time |
What enforcing actually does
The owner break-glass
Organisation owners are always exempt from enforcement. An owner keeps their password and can always sign in with it, plus two-factor authentication.
This is deliberate, and it is the single most important thing to understand about running single sign-on. Identity providers fail. Certificates expire, SAML metadata gets edited, an administrator leaves. If every account depended on your provider, one of those would lock your organisation out of its own data permanently. The owner exemption is the way back in.
You cannot enforce without a working break-glass
Certificates, and why they matter more than you expect
Your identity provider signs every sign-in with a certificate. That certificate has an expiry date, usually three to ten years out. When it expires, single sign-on stops working — and if you have enforcement on, everyone except owners is locked out until it is renewed.
Expired certificates are the most common cause of real single sign-on outages, precisely because the timescale is so long that nobody has a reminder. So we keep one for you.
What we do about it
- We read your provider’s certificate every day and record when it expires.
- We email your owners and administrators at 60, 30, 14, 7, 3 and 1 days before expiry, and daily once it has expired.
- The expiry date is shown in your single sign-on settings at any time.
- If your provider has no metadata URL, we start warning at 90 days instead, because renewing will need you to do something by hand.
We warn owners and administrators, not everyone. A warning two months before a date only an administrator can act on is noise for everyone else.
Why a metadata URL is worth having
If your provider publishes a metadata URL, we re-read it automatically. When your provider rotates its certificate, we pick the new one up on our own and your users never notice. Entra publishes several certificates at once during a rotation, which makes it seamless.
Google Workspace has no metadata URL
What happens on a downgrade
Single sign-on is an Enterprise feature. Plan changes are made by our team rather than from your settings, so if you move off Enterprise we will have spoken to you first. When that change is applied:
- Enforcement is switched off.
- Your verified domains are removed and the connection is disabled.
- Your owners and administrators get an email confirming it.
- Your users need to reset their password once to get back in, because enforcement had removed it. A normal “forgot password” from the sign-in page is all it takes.
Nothing is deleted. If you return to Enterprise you can set single sign-on up again, though you will re-verify your domains.
If something goes wrong
- Nobody can sign in and the certificate has expired. Renew it in your provider, then make sure we have the new metadata. An owner can still sign in with their password and two-factor authentication to make that change.
- A user is not being sent to your provider. Check that their email domain is one of your verified domains — matching is on the domain, not the individual address.
- You cannot switch enforcement on. No owner has both a password and two-factor authentication yet. Set those up on an owner account first.
Still stuck? Reply to any email from us, or use [email protected].