2026.08-sso2026-08-07

Per-tenant Single Sign-On

Per-tenant Single Sign-On

Plans: Growth and Scale Where: Organization → Sign-In Policy

Until now, “Sign in with Microsoft” meant signing in through autociso’s Microsoft app. Your IT team had no control over it, your conditional-access policies did not apply, and disabling someone in your directory did not stop them reaching autociso.

You can now connect your own identity provider instead.

What’s new

Bring your own identity provider

  • Google Workspace, Microsoft Entra ID, Okta, generic OIDC and generic SAML 2.0
  • You supply the client credentials; autociso never stores your client secret
  • A new connection starts as Pending and only becomes selectable after a successful Test connection
  • The values to paste into your provider (Redirect URI, or ACS URL and Entity ID for SAML) are shown on the page, ready to copy

Allowed Providers now decides what people are offered

Previously this list rejected a disallowed provider after someone had already signed in with it. It is now the sign-in policy itself: what you select is what your people see. Select only your own provider and there is no password field.

Removing Email / Password asks you to confirm, and autociso refuses any selection that would leave your organization with no way to sign in at all.

A copyable …/login/your-org link that sends your team straight to your identity provider, skipping the provider chooser. Share it or put it on your intranet.

Automatic account creation

Optional, off by default. When on, anyone your identity provider authenticates gets an account on first sign-in at a role you choose — Member, Contributor or Auditor. Never Owner or Manager.

Email domains

Optionally restrict which email domains may sign in to your organization. autociso will not let you save a list that excludes an Owner, including yourself.

Restore email & password sign-in

A one-press recovery action, available on every plan — including an expired trial — and to any Owner. It can only add password sign-in back; it never changes anything else. It exists so a billing state or a broken identity provider can never trap you outside your own compliance evidence.

Changes to existing behaviour

  • Every organization keeps password sign-in. A one-time update ensures Email / Password is present in every organization’s Allowed Providers before the new policy takes effect. Owners of any organization whose stored list did not include it were emailed.
  • Free and Seed plans keep the ability to choose among Email / Password, Google, GitHub and Microsoft. Connecting your own identity provider requires Growth or Scale. Nothing you had selected has changed.
  • System Managers can view the Sign-In Policy page but no longer see write controls on it, matching what the server has always enforced.

Not included yet

SCIM provisioning, group-to-role mapping, email-domain routing to a provider, multiple connections per organization, and IdP-initiated SAML. See the Single Sign-On reference for the full list and what each one would change.

Last reviewed: 2026-08-07

Was this page helpful?

Esc