Enterprise SSO & SCIM
- Written for
- + Written for
- Deprecated
- + Deprecated
- Applies to
- + Applies to
Enterprise SSO & SCIM
Large customers expect to manage access to your product through their identity provider (Okta, Microsoft Entra ID, Google Workspace, OneLogin…). Atlas lets you offer that without building SAML plumbing yourself.

The three pieces
SSO connection (SAML / OIDC) — the customer's IdP signs their employees in to your app. See SAML SSO setup.
Enforced SSO per domain — everyone with an
@customer.comemail must sign in through that IdP; no passwords or personal logins. See Enforced SSO & domains.SCIM provisioning — the IdP automatically creates, updates and deactivates user accounts as employees join, change teams or leave. See SCIM provisioning.
How it fits your organizations
Enterprise connections are scoped to an organization. A customer's IdP feeds people into their org, with roles mapped from IdP groups — so authorization keeps working exactly as it does for everyone else.
What your customer's admin does vs what you do
You (the app) | Your customer (the IdP admin) |
|---|---|
Create the org, enable an enterprise connection | Register Atlas as an application in their IdP |
Share the Atlas SP metadata / ACS URL | Provide IdP metadata / certificate |
Map IdP groups to Atlas roles | Assign employees and groups |
Enforce SSO for their domain | Manage the directory going forward |
Availability
Enterprise SSO, enforced SSO and SCIM are part of the Enterprise plan, which also includes an uptime SLA, data residency and a DPA. See Plans & billing or talk to sales.
Next
Set up the SSO connection → SAML SSO setup.