> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tryprofound.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Enterprise Single Sign-On (SSO) overview

> Supported protocols, scope, and how to get started with SSO configuration

<Info>
  **Available on**: the Enterprise plan

  **Find it in**: Settings in the organization name menu at the top left of the screen > Organization > Enterprise Setup

  **Required role**: Admin or custom
</Info>

Enterprise Single Sign-On (SSO) lets users sign in with their corporate identity provider (IdP) credentials, such as Microsoft Entra ID, Okta, or Google Workspace. Profound keeps their user data synchronized with the IdP.

## Supported protocols

Profound supports multiple protocols for enterprise SSO, including Security Assertion Markup Language (SAML) and OpenID Connect (OIDC). Setup is tailored to your IdP, and custom SAML and OIDC connections are available if your provider isn't among the commonly supported options.

## Domain matching and subdomain support

Authenticating with SSO requires the user's email domain to match the exact domain the connection is configured with. For example, a user with the email address `john-smith@tryprofound.com` can use SSO only with the `tryprofound.com` domain.

Subdomains (like `dev.tryprofound.com`) cannot use the same SSO connection as root domains (like `tryprofound.com`), so each subdomain needs its own connection.

Profound uses your verified domains to confirm that a user signing in belongs to your organization. You verify a domain by adding a DNS TXT record with a token generated by Profound. Learn more in [Domain verification](/platform-config/authentication/sso-domain-verification).

## SSO scope

SSO is configured per Profound organization. If your company operates multiple Profound organizations, each one needs its own SSO connection.

If your organizations share members, such as agency or contractor accounts, or have an otherwise non-standard configuration, contact your Engagement Manager for setup assistance.

## SSO and Directory Sync

SSO lets your IdP handle how users sign in. To also let it control who has access, with users provisioned and deprovisioned automatically, set up [Directory Sync](/platform-config/people/directory-sync). The features are independent: enable either one or both.

## Security controls

Your IdP decides how users prove who they are. You configure and enforce requirements such as multi-factor authentication (MFA), managed devices, network or location restrictions, and password rules in your IdP, and Profound accepts the result of that sign-in. See [Sign-in security and password requirements](/platform-config/authentication/sign-in-security) for what Profound enforces for password accounts and how sign-in works once SSO is enabled.

## Getting started

Follow the [Configure SSO guide](/platform-config/authentication/configure-sso) to set up SSO for your organization. If you need help, contact [customer support](mailto:support@tryprofound.com).
