# SSO (/docs/support/security/single-sign-on/sso)

You can connect your identity provider to Circleback so workspace members can log in with SSO. Circleback supports SAML and OIDC, so it works with Okta, Google Workspace, Microsoft Entra ID, and any other provider that supports either standard.

Once connected, workspace admins can enforce SSO, which disables every other way of logging in. Your identity provider decides who can access Circleback.

Circleback also works with SCIM, so your identity provider can manage accounts for you. When someone joins your company, they get access to Circleback automatically. When they leave, they're deactivated in your workspace.

## Connect your identity provider

1. Go to Settings → General (under Workspace).
2. Under **Single sign-on**, select **Connect**.
3. Choose **SAML** or **OIDC**, then select **Continue**.
4. Create an application in your identity provider using the values shown in Circleback, then enter your provider's details in Circleback. Follow the guide for your provider below.
5. Select **Continue**.
6. Leave **No directory sync** selected if you only need SSO, or choose a directory provider to set up SCIM. Select **Connect**.

Use one of these guides to configure your identity provider:

- [Google Workspace](/docs/support/security/single-sign-on/set-up-sso-with-google-workspace)
- [Microsoft Entra ID](/docs/support/security/single-sign-on/set-up-sso-with-microsoft-entra-id)
- [Okta](/docs/support/security/single-sign-on/set-up-sso-with-okta)

For other providers, follow the [SAML](/docs/support/security/single-sign-on/set-up-sso-with-saml) or [OpenID Connect](/docs/support/security/single-sign-on/set-up-sso-with-openid-connect) guide.

You can connect one identity provider per workspace. To switch providers, disconnect the existing connection first.

## Set up directory sync

Directory sync uses SCIM to add or deactivate workspace members through your identity provider. It is optional and separate from SSO.

On the **Directory sync** step, select **Microsoft Entra ID**, **Okta**, or **Generic SCIM 2.0** if you plan to set up provisioning with that provider. After you select **Connect**, Circleback shows a **Directory endpoint** and **Directory token**. Copy these into your provider's SCIM provisioning settings, then select **Done** in Circleback. Keep the directory token private.

For Google Workspace SAML setup, leave **No directory sync** selected.

Directory sync only manages members whose email domain matches a verified workspace domain. It cannot deactivate the billing owner or the only remaining workspace admin.

## Enforce SSO for your workspace

Connecting an identity provider does not require members to use it. To require SSO, go to Settings → General (under Workspace) and turn on **Enforce SSO** under **Single sign-on**.

When you turn it on, other workspace members not logged in with SSO are signed out. They must log back in through your identity provider.

Keep your current Circleback window open. In a private browser, go to the Circleback login page and enter your work email to check that you can log in through your identity provider. If you cannot log in, use your open admin session to turn off **Enforce SSO** while you check the setup.

## How Circleback access works without SSO

Each time you log in to Circleback, we send a unique login code directly to your work email. If access to your work email is protected via your organization’s single sign-on (SSO) or multi-factor authentication (MFA), then Circleback inherits these protections as well. This ensures your access to Circleback remains just as secure as your company email.

Additionally, when a member is deactivated on your team, they are signed out of Circleback on all devices.