Enterprise SSO lets the team sign in with existing company credentials (e.g. Okta, Azure AD, Google Workspace) instead of a separate Microspace password.
What it does
Team members sign in with their existing company credentials
No separate Microspace password to remember or reset
Login can be restricted to verified company email domain(s)
Supports SAML and OIDC-based identity providers
How to get it enabled
Contact your account manager to get it enabled. Your IT team will need to be involved to provide identity provider information, including:
The identity provider (Okta, Azure AD, Google Workspace, etc.)
The email domain(s) the team logs in with
Allowed domains are confirmed before enforcement is turned on.
What changes once SSO is enabled
Anyone logging in with an email on the verified domain is redirected to the company login screen
New team members invited afterward must also authenticate via SSO
Existing password-based accounts on the domain stop working for login; SSO should be used going forward
If someone can't log in
"SSO login required" - the account's email domain belongs to an SSO-enforced organization; use the company login instead of email/password
"Email domain not allowed" - the email isn't on the organization's approved domain list; contact an admin or Microspace support to add it
Notes
Enterprise SSO is included in the Enterprise plan, and available as an add-on for other plans.
Turning SSO off also requires Microspace support.
