Signing in with SSO doesn’t add anyone to the organization. To add users, see Manage Team.
Set up an SSO connection
The guide for your SAML IdP takes you through each part of the setup:- Creating the SAML app in the IdP.
- Registering it in StackOne.
- Verifying the domain.
- Managing the connection afterward.
Okta
Microsoft Entra ID
Other SAML 2.0 provider
Require SSO
Once the domain is verified, you can require users to sign in through SSO and turn off email and password sign-in.- Go to Organization > Security > Authentication.
- On the Enforcement Policy card, select Edit policy.
- Add the SAML connection to Enforced methods.
- Select Save changes.

Locked out after enforcing? An Organization Admin who can still reach the dashboard can remove the method from the Enforcement Policy to restore password sign-in. If no one can get in, contact StackOne support.
Next steps
Just-in-Time Provisioning
Add users who aren’t members yet when they sign in, and map an attribute to organization admin.
SCIM Provisioning
Provision and deactivate members automatically from the IdP.
Groups
Grant many members the same project or account access at once.