Single Sign-On (SSO)
Single sign-on (SSO)
Configure authentication for access to the Zefi Dashboard with an Identity Provider.
Single Sign-On (SSO) allows your team to sign in through an Identity Provider (IdP) using one set of credentials and access multiple applications, such as Zefi. Enabling SSO for your team increases security and makes it easier for them to sign in to Zefi. Zefi specifically supports Security Assertion Markup Language (SAML) 2.0, so your IdP can manage the creation of user accounts (team members) as well as authentication and authorization during sign-in. Any identity provider that supports SAML 2.0 works with Zefi.
Security Incidents:
If your Identity Provider (IdP) is compromised, unauthorized parties could access your Zefi account. You’re responsible for mitigating your exposure to security incidents by evaluating your security needs and implementing the necessary security protocols and controls.
Setup SSO with an Identity Provider
[Okta
\Learn how to setup single sign-on in the Dashboard with Okta.
\Discover more
\ [Google Workspace
\Learn how to setup single sign-on in the Dashboard with Google Workspace.
\Discover more
\ [**Auth0**
\Learn how to setup single sign-on in the Dashboard with Auth0.
\Coming soon ...](/content/single-sign-on-sso#/index.html) [****Entra ID****
\Learn how to setup single sign-on in the Dashboard with Entra ID (formerly known as Azure AD).
\Coming soon ...](/content/single-sign-on-sso#/index.html) [****OneLogin****
\Learn how to setup single sign-on in the Dashboard with OneLogin.
\Coming soon ...](/content/single-sign-on-sso#/index.html) [****Other****
\Learn how to setup single sign-on in the Dashboard with a different identity provider.
\Coming soon ...](/content/single-sign-on-sso#/index.html)
Additional resources
[Consolidate SSO
\Learn how to consolidate single sign-on (SSO) settings across multiple accounts.
\Discover more
\ [Troubleshoot SSO
\Learn how to resolve failed configuration checks when setting up SSO.
\Discover more
\
Supported features
Zefi supports the following SSO features:
.svg)
SSO configuration options:
Configure Zefi accounts to either mandate SSO for all users or allow sign-in using SSO or email and password.
.svg)
Just-In-Time account creation:
Automatically create new Zefi accounts for users without existing access upon their first SSO sign-in.
.svg)
Granular Dashboard roles: Assign granular user roles through your IdP.
.svg)
IdP-initiated SSO:
Authenticate directly from an IdP’s website or browser extension.
.svg)
Service Provider-initiated SSO:
Initiate SSO login directly from Zefi’s login page.
.svg)
System for Cross-domain Identity Management (SCIM):
SCIM is a protocol that an IdP can use to synchronize user identity lifecycle processes (for example, provisioning and deprovisioning access, and populating user details) with the service provider, such as Zefi.
Limitations
Zefi doesn’t support the following SSO features:
User Deletion in SAML:
When users aren’t managed through SCIM, Zefi doesn’t receive immediate notifications if user access is revoked in IdP. If users attempt to log in through SSO after their session expires, Zefi revokes their access. To remove access immediately, you can delete users from your team settings or enable SCIM user provisioning.