Skip to main content
Configure a SAML connection so your team signs in to Control through your identity provider. Use this when your organization requires single sign-on for access control, provisioning consistency, or audit compliance.

Availability

The Security & SSO section appears in Settings only when both conditions are met:
  • Your membership role in the active organization is Owner or Admin.
  • Self-serve SSO has been enabled for your organization by Control.
If the section is not visible, contact Control support to request self-serve SSO for your organization.

Before you begin

  • Confirm you can create a SAML application in your identity provider (for example, Microsoft Entra ID, Okta, or Google Workspace).
  • Have the domain or domains that your users sign in with ready to verify.
  • Coordinate with your identity provider administrator if you do not manage it yourself.

Open the SSO settings

  1. In Control, open .
  2. Under Organization, select Security & SSO.
  3. Select Manage enterprise SSO.
Control opens the Organization Profile Security tab, where you verify domains and configure the SAML connection.

Configure the SAML connection

  1. In the Security tab, add and verify each domain your users sign in with.
  2. Create a new enterprise SSO connection and choose SAML.
  3. Exchange the metadata between Control and your identity provider:
    • Copy the Assertion Consumer Service (ACS) URL and Entity ID from Control into your identity provider’s SAML application.
    • Copy the identity provider metadata URL or certificate back into Control.
  4. Map the required user attributes (typically email, first name, and last name).
  5. Save the connection and enable it for the verified domains.

Verify the result

  1. Sign out of Control.
  2. Sign in with an email address on a verified domain.
  3. Confirm the browser is redirected to your identity provider and back to Control.
New users who sign in through the connection are added to your organization automatically.

Troubleshooting