Single Sign-On (SSO)
How an organization administrator sets up enterprise Single Sign-On (SSO) for Archera, and how to require SSO for all users.
Last updated
Was this helpful?
How an organization administrator sets up enterprise Single Sign-On (SSO) for Archera, and how to require SSO for all users.
Archera supports enterprise Single Sign-On so your team can sign in with your existing identity provider. SSO is powered by WorkOS and supports both SAML and OIDC connections with all major providers, including Okta, Microsoft Entra ID (Azure AD), Google Workspace, and OneLogin.
Setting up SSO requires the Organization → write permission. Most organization administrators have this. If the SSO controls are greyed out, ask an administrator to make the change.
Go to Settings → SSO in Archera.
Connection name (optional) — a label to help you identify this connection later.
Domains (required) — the email domain(s) whose users should sign in through SSO. Separate multiple domains with commas. Your organization's domain is pre-filled. Any user with a matching email domain will be routed to SSO when they sign in.
The connection is active once it is enabled, its domain matches the user's email, and setup is complete in the WorkOS portal. There is no separate activation or in-app test step.
For step-by-step setup with a specific provider, see Configure SSO for Azure AD. Instructions for Okta, Google Workspace, and other providers are shown inside the WorkOS admin portal during setup.
Each connection in the SSO Configurations list has an options menu:
Manage — reopens the WorkOS admin portal to change provider settings.
Enable / Disable — turn the connection on or off. Disabled connections are marked accordingly.
Delete — remove the connection (this also removes it in WorkOS).
Domains cannot be edited in Archera after a connection is created — the in-app menu only offers Manage, Enable/Disable, and Delete. To change domains or provider details, use Manage to edit in the WorkOS portal, or delete the connection and create a new one.
At the top of the SSO tab, SSO General Settings includes an SSO Only toggle: "Require all users to authenticate via SSO." Turning it on disables email/password login and forces users to sign in through SSO.
Enable SSO Only only after you have confirmed SSO works for your team. Note that SSO Only applies to users whose account belongs to a single organization; a user who is a member of more than one organization is not forced through SSO by this setting.
Questions or issues during setup? Reach out to support@archera.ai.
Last updated
Was this helpful?
Was this helpful?

