With Single Sign-On (SSO), your team logs in to ChangeTower with your company's existing identity provider (IdP), such as Microsoft Entra ID or Google Workspace, over SAML 2.0. SSO isn't self-service in the app yet, so our team sets it up with you.
Why use SSO
Manage authentication and accounts in one place
Apply your IdP's security policies, like MFA and password rotation
Give your team a faster login
Step 1: Collect your IdP details
From your identity provider, gather:
Metadata file or URL with your SAML configuration
Entity ID
SSO login URL
X.509 certificate (for signing/encryption)
If you're not sure where to find these, your IT administrator can help.
Step 2: Send them to our team
Email [email protected] to start the SSO configuration process.
Step 3: We configure SSO
Our team sets up SSO for your workspace. This usually takes 1–2 business days.
Step 4: Finish setup in your IdP
We'll send you the values to add in your IdP (such as the ACS URL and Entity ID) and confirm everything works.
Good to know
Plans: SSO is available on the Enterprise plan. Talk to our team to learn more.
Supported providers: Any SAML 2.0 identity provider, including Microsoft Entra ID (Azure AD), Google Workspace, Okta, and OneLogin.
Self-service: You can't configure SSO yourself yet. Our team handles setup to make sure it's done correctly and securely.
