Availability
The Security & SSO section appears in Settings only when both conditions are met:
- Your membership role in the active organization is Owner or Admin.
- Self-serve SSO has been enabled for your organization by Control.
Before you begin
- Confirm you can create a SAML application in your identity provider (for example, Microsoft Entra ID, Okta, or Google Workspace).
- Have the domain or domains that your users sign in with ready to verify.
- Coordinate with your identity provider administrator if you do not manage it yourself.
Open the SSO settings
- In Control, open .
- Under Organization, select Security & SSO.
- Select Manage enterprise SSO.
Configure the SAML connection
- In the Security tab, add and verify each domain your users sign in with.
- Create a new enterprise SSO connection and choose SAML.
- Exchange the metadata between Control and your identity provider:
- Copy the Assertion Consumer Service (ACS) URL and Entity ID from Control into your identity provider’s SAML application.
- Copy the identity provider metadata URL or certificate back into Control.
- Map the required user attributes (typically email, first name, and last name).
- Save the connection and enable it for the verified domains.
Verify the result
- Sign out of Control.
- Sign in with an email address on a verified domain.
- Confirm the browser is redirected to your identity provider and back to Control.