Skip to main content

How do I set up Single Sign-On (SSO)?

Learn how to set up Single Sign-On so your team can log in to ChangeTower through your company's identity provider, such as Microsoft Entra ID or Google Workspace. This keeps access secure and managed in one place.

With Single Sign-On (SSO), your team logs in to ChangeTower with your company's existing identity provider (IdP), such as Microsoft Entra ID or Google Workspace, over SAML 2.0. SSO isn't self-service in the app yet, so our team sets it up with you.

Why use SSO

  • Manage authentication and accounts in one place

  • Apply your IdP's security policies, like MFA and password rotation

  • Give your team a faster login

Step 1: Collect your IdP details

From your identity provider, gather:

  • Metadata file or URL with your SAML configuration

  • Entity ID

  • SSO login URL

  • X.509 certificate (for signing/encryption)

If you're not sure where to find these, your IT administrator can help.

Step 2: Send them to our team

Email [email protected] to start the SSO configuration process.

Step 3: We configure SSO

Our team sets up SSO for your workspace. This usually takes 1–2 business days.

Step 4: Finish setup in your IdP

We'll send you the values to add in your IdP (such as the ACS URL and Entity ID) and confirm everything works.

Good to know

  • Plans: SSO is available on the Enterprise plan. Talk to our team to learn more.

  • Supported providers: Any SAML 2.0 identity provider, including Microsoft Entra ID (Azure AD), Google Workspace, Okta, and OneLogin.

  • Self-service: You can't configure SSO yourself yet. Our team handles setup to make sure it's done correctly and securely.

Did this answer your question?