> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tryprofound.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure SSO

> Set up Single Sign-On with Profound over SAML or OIDC

Set up Single Sign-On (SSO) with Profound over Security Assertion Markup Language (SAML) or OpenID Connect (OIDC). Profound supports various identity providers (IdPs), including Microsoft Azure AD, Google Workspace, Okta, and any custom SAML-compliant or OIDC-compliant IdP.

<Info>
  **QUICK FACTS**

  * SSO setup is **self-serve**. Anyone can complete it and pass the values to their IT team.
  * You set up SSO in the configuration portal, which **takes you outside Profound**.
  * **Exit the setup and come back anytime**. The values you entered or generated stay in place, and your team keeps signing in as usual until you enable SSO in the last step of the setup guide.
  * **Profound doesn't publish fixed SSO connection values** such as the ACS URL, Entity ID, or Redirect URI, and you don't need to request them. The portal generates them for your organization as you follow the [setup steps](#setup-steps).
</Info>

## Before you start

You'll need:

* The [Admin role](/platform-config/people/roles-and-permissions) in your Profound organization
* Administrative access to your IdP
* The domain you want to enable for SSO
* An account in your IdP on the SSO domain, for running the test sign-in
* Access to your DNS records to verify domain ownership

## Setup steps

<Steps>
  <Step title="Open the SSO configuration portal" id="step-1">
    1. In Profound, select your organization name at the top left of the screen, then select **Settings**.
    2. Select **Enterprise Setup** under **Organization** in the left navigation sidebar. The **Single Sign-On** card shows your current SSO status and verified domains.
    3. Select **Configure SSO** to open the configuration portal.

           <img src="https://mintcdn.com/profound-37face47/KA2VQvbNybfiIidf/images/enterprise-connections/sso-configure.png?fit=max&auto=format&n=KA2VQvbNybfiIidf&q=85&s=7ffcd1116e918e85a10ca092d912ffc3" alt="Enterprise Setup page screenshot showing the Single Sign-On card with the Configure SSO button highlighted" width="1760" height="1084" data-path="images/enterprise-connections/sso-configure.png" />
  </Step>

  <Step title="Verify your domain" id="step-2">
    The portal takes you to the domain verification step. Follow it as described in [Domain verification guide](/platform-config/authentication/sso-domain-verification). The remaining steps become available after the domain is verified.

    <Note>
      This step is for adding a DNS record, not for connecting your IdP. You select your IdP, such as Okta or Microsoft Entra ID, in the next step.
    </Note>

    Profound checks the email domain of each user who signs in through your IdP against your verified domains, and rejects the sign-in when it doesn't match or when your organization has no verified domains.

    After your domain is verified, the **Single Sign-On** card shows the status **In progress** until you enable SSO.
  </Step>

  <Step title="Select your identity provider" id="step-3">
    Select your IdP from the list of supported options. After you select it, the portal shows setup instructions specific to your provider.

    If your provider isn't on the list, use the custom SAML or OIDC connection option. If you run your own authorization server rather than a commercial IdP, use the custom OIDC connection option.
  </Step>

  <Step title="Follow the IdP-specific instructions" id="step-4">
    The portal walks you through connecting your IdP to Profound. It shows the values to copy from Profound into your IdP, and the values to retrieve from your IdP and enter into the portal. Copy the Profound values from the portal. They're generated per SSO connection and don't appear anywhere else in Profound.

    The values you exchange depend on your SSO protocol:

    <Tabs>
      <Tab title="OIDC">
        * Profound → IdP: the Authorized Redirect URI
        * IdP → Profound: the Discovery Endpoint, Client ID, and Client Secret
      </Tab>

      <Tab title="SAML">
        * Profound → IdP: the ACS URL, Service Provider Entity ID, and Metadata URL
        * IdP → Profound: the SSO URL, Entity ID, and X.509 Certificate
      </Tab>
    </Tabs>

    Follow the instructions shown in the portal for your specific IdP and protocol.
  </Step>

  <Step title="Test the connection" id="step-5">
    The final step in the portal validates your connection. Select **Test sign-in** to run a real sign-in through your IdP. The portal redirects you to your IdP, you sign in with an account on the domain you verified, and your IdP returns you to the portal with the result:

    * **Test successful**: your IdP returned a valid response and the connection is configured correctly.
    * **Test failed**: the portal shows the validation error and debugging steps. Repeat [Step 4](#step-4) to correct the connection values, then run the test again.

    Run the test as many times as you need. The portal records each attempt in the **Sessions** list on its SSO screen. Select a session to see the request sent to your IdP and the response it returned. These details help when you troubleshoot with your IdP administrator or Profound's [customer support](mailto:support@tryprofound.com).

    **Notes**:

    * Testing happens in your own Profound organization, a separate test organization isn't needed.
    * Running a test sign-in only affects the account you test with.
    * Your team keeps signing in as usual until you enable SSO in the next step.

    To start over with a different IdP or protocol, select **Reset Connection** in the portal and follow the prompts.
  </Step>

  <Step title="Enable SSO" id="step-6">
    After the test passes, enable SSO for your domain directly from the portal. Back on the **Enterprise Setup** page, the status reads **SSO Enabled** and your domain is marked **Verified**. Select **Check status** to refresh.

    <img src="https://mintcdn.com/profound-37face47/KA2VQvbNybfiIidf/images/enterprise-connections/sso-success.png?fit=max&auto=format&n=KA2VQvbNybfiIidf&q=85&s=dc627643c2263f21df478dd6f75c7ff2" alt="Enterprise Setup page screenshot showing SSO Enabled status, a Verified domain, and the Check status button highlighted" width="1766" height="862" data-path="images/enterprise-connections/sso-success.png" />
  </Step>
</Steps>

After you enable SSO, Profound automatically directs users whose email addresses match your configured domains to your IdP for authentication.

## Notes

* Each Profound organization needs its own SSO connection.
* Subdomains can't use the same SSO connection as the root domain: each subdomain needs its own connection.
* Keep each domain's verification TXT record in place for as long as SSO is enabled for that domain.
* For SAML connections, renew your IdP signing certificate before it expires. The **Single Sign-On** card shows a warning as the expiry date approaches.
* Contact [customer support](mailto:support@tryprofound.com) if you need help during setup.
