SSO and SCIM are available on the Growth and Enterprise plans. This guide covers the most common identity providers: Okta, Microsoft Entra ID, and Google Workspace.
Prerequisites
- Owner or Admin role on the workspace.
- Admin access to your identity provider.
- A verified domain (Settings → Domains).
Okta
Create a new SAML 2.0 application in Okta. Use the ACS URL and Entity ID shown under Settings → Security → SSO. Map the following attributes:
email→ user.emailfirstName→ user.firstNamelastName→ user.lastName
Microsoft Entra ID
Use the Enterprise Applications gallery and search for KaryaFlow™. The federation setup is one-click. For SCIM provisioning, use the token shown under Settings → Security → SCIM.
Session policies
Enforce session length, idle timeout, and IP allowlists from Settings → Security → Sessions. Enterprise plans can also require device posture checks via your MDM.
