Single sign-on (SSO)
Let people sign in to Fuxam with your organization's identity provider — set up SAML enterprise connections, manage the email domains that route to them, and auto-sync domains as users join.
Single sign-on (SSO) lets the people in your institution sign in to Fuxam with the same account they already use elsewhere — for example, your Microsoft Entra ID, Okta, or Google Workspace login — instead of a separate Fuxam password. You connect Fuxam to your identity provider (IdP) once, tell Fuxam which email domains belong to your organization, and matching users are routed to your login screen automatically.
SSO is configured in institution Settings → Subdomain SSO. Because it applies to your whole organization rather than a single product, it lives in Fuxam Base alongside the other institution-wide foundations.
Why it matters
For an institution, SSO removes a whole class of day-to-day friction and risk. People stop maintaining a separate Fuxam password, so there are fewer forgotten-password tickets and fewer weak or reused credentials. When someone leaves and you disable their account in your identity provider, their Fuxam access ends at the same moment — no orphaned logins. And because sign-in flows through your existing provider, any multi-factor authentication or conditional-access policy you already enforce automatically covers Fuxam too.
How it fits together
SSO connects three things: your identity provider, one or more enterprise connections in Fuxam, and the email domains that decide who uses each connection.
- An enterprise connection is the trust relationship between Fuxam and one identity provider, established over SAML.
- Each connection owns a set of email domains. When someone enters an email on a matching domain, Fuxam sends them to that connection’s provider to sign in.
- People whose email does not match any connection continue to sign in with a Fuxam password.
- Optionally, you can force SSO on your institution subdomain so that everyone visiting your dedicated Fuxam address is sent straight to your provider.
Key concepts
| Term | Meaning |
|---|---|
| Identity provider (IdP) | The external service that authenticates your people — for example, Microsoft Entra ID, Okta, or Google Workspace. |
| Enterprise connection | A configured SSO link between Fuxam and one identity provider, based on SAML. |
| Service provider (SP) | Fuxam’s side of the SAML relationship. The IdP setup guide gives you the SP values (such as the ACS URL and entity ID) your provider needs. |
| Email domain | The part of an address after the @ (for example, university.edu). Domains attached to a connection route matching users to that connection. |
| Active / inactive connection | Only an active connection routes real sign-ins. A new connection stays inactive until setup is complete and you activate it. |
| Force subdomain SSO | An institution-wide option that sends everyone on your Fuxam subdomain to SSO by default. |
| Auto-sync new users | A per-connection option that adds a new member’s email domain to the connection automatically as people join. |
Where to start
A typical rollout runs in this order:
- Gather your identity provider’s SAML details (or the metadata URL/file).
- Set up an SSO connection — create it, exchange configuration with your provider, and activate it.
- Manage its email domains — add the domains that should use it, sync domains from your existing users, and decide whether to keep them in sync automatically.
- Test a sign-in with an account on a matching domain before rolling out to everyone.
In this section
Set up an SSO connection
Create an enterprise connection, exchange SAML configuration with your identity provider, and activate it.
Manage email domains
Add and remove domains, sync them from existing users, handle public-domain limits, and auto-sync new users.
Related pages
- Roles and permissions — the access right that controls who can manage SSO.
- Create a user — how new members are added, which can also feed domain auto-sync.
- Fuxam Base — the other institution-wide foundations SSO sits alongside.