> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mention-me.com/llms.txt
> Use this file to discover all available pages before exploring further.

# How to Set Up Single Sign-On

> Verify the email domains your organisation uses, then connect your identity provider.

export const AdminOnly = () => <Info>
    This page is visible to organisation <strong>admins</strong> only. If you
    see <strong>You do not have permission to view this page</strong>, ask an
    admin to make the change, or to invite you with the Admin role.
  </Info>;

<AdminOnly />

Open **Settings > Single sign-on** to require people with a matching email domain to sign in through your identity provider.

This is where an organisation without single sign-on sets it up. Classic **Security & Data** no longer has a setup form.

You must verify each domain before the connection can be configured. **Continue** stays unavailable until every domain you add shows **Verified**.

<Warning>
  Only add domains your organisation controls. A verified domain decides who
  must use your identity provider to sign in.
</Warning>

## Verify Your Domains

<Steps>
  <Step title="Open Single Sign-On">
    Go to **Settings > Single sign-on**.
  </Step>

  <Step title="Start Configuration">
    Click **Start configuration**. If a setup is already in progress, click
    **Continue configuration**.
  </Step>

  <Step title="Add Each Domain">
    On **Add SSO domains**, type the domain people use in their work email,
    such as `acme.com`, and click **Add**.

    If your own email already uses that domain, the page offers to add it.
    Use that instead of typing the domain.
  </Step>

  <Step title="Publish the DNS Record">
    Each new domain shows a TXT record with **Type**, **Host / Name**, and
    **Value**. Create that record with your DNS provider.

    The page checks the record for you. The domain stays **Unverified** until
    the record is found, then it shows **Verified**.
  </Step>

  <Step title="Continue">
    Repeat for every domain people use to sign in. Click **Continue** once
    every domain is **Verified**.
  </Step>
</Steps>

At least one verified domain is required. You cannot remove the last one while you are setting SSO up, or after it is active.

If a domain shows **Expired**, click **Verify again** and publish the new TXT record.

People whose email domain is not in this list can still sign in with their existing method.

## Connect Your Identity Provider

After the domains are verified, the setup continues through **Connection**, **Test**, and **Activate**.

On **Connection**, choose the provider and follow the values on the page:

* Google Workspace, Okta, and Microsoft Entra use SAML.
* Auth0 and a custom provider use OpenID Connect (OIDC).

Create a new application in the identity provider for this connection.

On **Test**, open the test URL and sign in with an email on a verified domain. You need one successful test before you can continue.

On **Activate**, click **Activate SSO**. After that, anyone signing in with a verified domain must use the identity provider.

<Info>
  Activate applies to Mention Me. Classic keeps its current sign-in until an
  admin confirms the switch. If the organisation already has SSO on Classic, see
  [Updating Your SSO Connection](/knowledge/security/account/sso-migration).
</Info>

## See Also

<CardGroup cols={2}>
  <Card title="How to Manage Organisation Members" icon="users" href="/knowledge-app/settings/organisation/members">
    Invite colleagues and change their roles.
  </Card>

  <Card title="Updating Your SSO Connection" icon="key" href="/knowledge/security/account/sso-migration">
    Move an existing Classic SSO connection, then confirm the switch on Mention
    Me.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.