e5ac9f5b8b
Follow-up based on comments from https://github.com/twentyhq/twenty/pull/23266 <!-- This is an auto-generated description by cubic. --> <a href="https://cubic.dev/pr/twentyhq/twenty/pull/23429?utm_source=github" target="_blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)" srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img alt="Review in cubic" src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a> <!-- End of auto-generated description by cubic. --> --------- Co-authored-by: Félix Malfait <felix@twenty.com> Co-authored-by: cubic-dev-ai[bot] <191113872+cubic-dev-ai[bot]@users.noreply.github.com>
106 lines
3.4 KiB
Plaintext
106 lines
3.4 KiB
Plaintext
---
|
|
title: SSO Configuration
|
|
description: Configure Single Sign-On for secure enterprise authentication.
|
|
---
|
|
|
|
## About SSO
|
|
|
|
Single Sign-On (SSO) allows your team members to log into Twenty using your organization's identity provider. This provides:
|
|
- **Centralized access control**: Manage access from one place
|
|
- **Enhanced security**: Leverage your existing security policies
|
|
- **Better user experience**: One set of credentials for all tools
|
|
|
|
## Supported Providers
|
|
|
|
Twenty supports SSO with:
|
|
- **SAML 2.0**: Works with most enterprise identity providers
|
|
- **Google Workspace**: For organizations using Google
|
|
- **Microsoft Entra ID** (formerly Azure AD): For Microsoft environments
|
|
|
|
## Setting Up SSO
|
|
|
|
### Prerequisites
|
|
- Organization plan (cloud and self-hosted workspaces)
|
|
- Admin access to your identity provider
|
|
- Admin access to your Twenty workspace
|
|
|
|
### Configuration Steps
|
|
|
|
#### 1. Access SSO Settings
|
|
1. Go to **Settings → Security**
|
|
2. Find the **SSO Configuration** section
|
|
3. Click **Configure SSO**
|
|
|
|
#### 2. Choose Your Provider
|
|
Select your identity provider from the list or choose "Custom SAML" for other providers.
|
|
|
|
#### 3. Configure Your Identity Provider
|
|
You'll need to configure your identity provider with:
|
|
- **Entity ID**: Provided by Twenty
|
|
- **ACS URL**: The callback URL for authentication
|
|
- **Certificate**: For secure communication
|
|
|
|
#### 4. Enter Provider Details in Twenty
|
|
- **SSO URL**: Login URL from your provider
|
|
- **Entity ID**: Your provider's identifier
|
|
- **Certificate**: X.509 certificate from your provider
|
|
|
|
#### 5. Test and Enable
|
|
1. Click **Test Configuration** to verify setup
|
|
2. Enable SSO when testing is successful
|
|
3. Configure user provisioning preferences
|
|
|
|
## User Provisioning
|
|
|
|
### Just-in-Time (JIT) Provisioning
|
|
- Users are created automatically on first login
|
|
- Users are assigned a default role automatically
|
|
- No manual user creation needed
|
|
|
|
### Manual Provisioning
|
|
- Invite users before they can log in
|
|
- Pre-assign specific roles
|
|
- More control over who can access the workspace
|
|
|
|
## Managing SSO Users
|
|
|
|
### Role Assignment
|
|
SSO users can be assigned roles like regular users:
|
|
1. Go to **Settings → Members**
|
|
2. Find the user
|
|
3. Change their role as needed
|
|
|
|
### Access Revocation
|
|
To remove access for SSO users:
|
|
- Remove them from your identity provider, or
|
|
- Remove them from the Twenty workspace
|
|
|
|
## Best Practices
|
|
|
|
### Security
|
|
- **Require SSO**: Disable password login for SSO users
|
|
- **Regular audits**: Review access periodically
|
|
- **Strong IdP policies**: Enforce MFA at the identity provider
|
|
|
|
### User Management
|
|
- **Clear naming**: Use consistent naming from your directory
|
|
- **Group mapping**: Map IdP groups to Twenty roles (if available)
|
|
- **Offboarding process**: Include Twenty in your deprovisioning workflow
|
|
|
|
## Troubleshooting
|
|
|
|
### Common Issues
|
|
- **Certificate errors**: Ensure the certificate hasn't expired
|
|
- **URL mismatches**: Verify the ACS URL matches exactly
|
|
- **User not found**: Check JIT provisioning settings
|
|
|
|
### Getting Help
|
|
If you encounter issues, contact support with:
|
|
- Error messages received
|
|
- Identity provider being used
|
|
- Configuration details (without sensitive data)
|
|
|
|
<Tip>
|
|
Need SSO configured for your organization? [Find a certified Twenty partner](https://twenty.com/partners/list?categories=SOLUTIONING&ref=docs-sso) who specializes in SSO and identity setup. *(Prefer to loop in Twenty directly? [contact@twenty.com](mailto:contact@twenty.com))*
|
|
</Tip>
|