Skip to content

Managed Deployment SSO Setup

  • Managed deployment

Connect your organization's identity provider so users can sign in with their work accounts and follow your organization's MFA and sign-in policies. Administrators configure OpenID Connect (OIDC), SAML 2.0, and email and password sign-in directly in Settings > Access > Providers.

Permissions

You need the Admin role in Qualytics and permission to configure an application in your identity provider. Your Qualytics account team can help with onboarding and configuration.

Establish Administrator Access

If no personal account has been created, open the deployment URL, complete the initial administrator form, and click Create Administrator. The account receives the Admin role. If onboarding has already established an administrator, use the invitation or sign-in method arranged with that administrator.

Keep a working administrator sign-in available throughout SSO setup. Email and password sign-in can remain enabled alongside SSO, because enabling SSO does not disable it automatically.

Connect Your Identity Provider

  • OpenID Connect


    Connect an OIDC provider such as Microsoft Entra ID, Okta, Google Workspace, or Keycloak. Copy the Redirect URI displayed after creating the provider into your identity provider's application registration.

    Add an OIDC Provider

  • SAML 2.0


    Connect a SAML identity provider using its metadata. Use the service provider metadata from Qualytics to configure the application in your identity provider.

    Add a SAML Provider

Use the values generated for your provider and deployment. Another deployment's callback address or service provider metadata will not complete your sign-in setup.

Verify Sign-In and Access

  1. Configure who can sign in using the provider's Allowed Email Domains, Allowed Groups, and Automatic user provisioning settings.
  2. Review identity linking before admitting people who already have Qualytics accounts. Cross-provider account linking can attach their new sign-in identity to their existing account, and Require administrator approval holds new links for review.
  3. Run Test, resolve failed checks, and enable the provider. A successful diagnostic test does not replace a real sign-in.
  4. Open a separate browser session and complete sign-in with a representative user. Confirm the expected role and Team memberships.
  5. Repeat with an Admin account before changing any existing sign-in method.

For automated account and Team updates from your directory, configure Directory Sync. SSO authentication alone does not remove Team memberships when someone leaves a directory group.

Require SSO

If your policy requires SSO for customer accounts, sign in as an Admin through the verified SSO provider and disable Email & Password sign-in. Qualytics prevents disabling the provider used by your current session or the last enabled customer sign-in provider.

Disabling password sign-in ends sessions issued through that provider. Email invitations for password accounts and password resets are unavailable while it is disabled. You can keep multiple SSO providers enabled.

Ongoing Administration

  • Change credentials: edit the provider when your identity provider's client secret or certificate changes. Security-sensitive changes end affected sessions, and users sign in again.
  • Revoke access immediately: deactivate the user in Qualytics or use Directory Sync. Session behavior after an identity provider change depends on the provider. See Sessions.
  • Investigate sign-in problems: review Settings > Access > Log, provider diagnostics, and pending Link approvals.

See Sign-In Providers for password policies, linking, permissions, and detailed setup. Self-hosted operators should also review Self-Hosted Authentication Setup.