Choose a guide
Okta
Okta is your enterprise IdP
Azure AD
Microsoft Entra ID / Azure AD
Custom SAML
Any other SAML 2.0–compatible IdP (Ping, OneLogin, Auth0, etc.)
Team SSO
Each team or sub-team brings its own IdP
Email & password
Sign in with email and password
Google sign-in
Sign in with a Google account
How platform SSO works
- An admin creates a SAML application in your IdP (ACS URL, Entity ID, Name ID, attributes).
- You collect the IdP metadata URL (or metadata XML) and your enterprise email domain.
- You send those details to Support (provider name, domain, metadata, and whether SSO Sign-In Only should apply).
- EKB configures and tests the connection on your instance, then enables SSO for that domain.
SSO Sign-In Only
When SSO Sign-In Only is enabled for a domain, users with that email domain must use SSO. Email/password sign-in and password reset are disabled for them. Request this flag when you submit the IdP details to Support, or confirm it with your EKB admin if it is managed in-product for your deployment.What to send Support
Related
- Okta SSO
- Azure AD SSO
- Custom SSO
- Team SSO
- Account Settings (team “allow only SSO” style controls, when available)