---
title: Single sign-on (SSO)
description: >-
  Let people sign in to Fuxam with your organization's identity provider — set
  up SAML enterprise connections, manage the email domains that route to them,
  and auto-sync domains as users join.
sidebar:
  order: 5
---

**Single sign-on (SSO)** lets the people in your institution sign in to Fuxam with the same account they already use elsewhere — for example, your Microsoft Entra ID, Okta, or Google Workspace login — instead of a separate Fuxam password. You connect Fuxam to your **identity provider (IdP)** once, tell Fuxam which **email domains** belong to your organization, and matching users are routed to your login screen automatically.

SSO is configured in institution **Settings → Subdomain SSO**. Because it applies to your whole organization rather than a single product, it lives in **Settings** alongside the other institution-wide settings.

:::info
SSO settings require the **Update settings** permission. If **Subdomain SSO** is missing from your Settings sidebar, ask an administrator to grant it — see [Roles and permissions](/docs/fuxam-web/base/user-management/roles-and-permissions).
:::

## Why it matters

For an institution, SSO removes a whole class of day-to-day friction and risk. People stop maintaining a separate Fuxam password, so there are fewer forgotten-password tickets and fewer weak or reused credentials. When someone leaves and you disable their account in your identity provider, their Fuxam access ends at the same moment — no orphaned logins. And because sign-in flows through your existing provider, any multi-factor authentication or conditional-access policy you already enforce automatically covers Fuxam too.

## How it fits together

SSO connects three things: your **identity provider**, one or more **enterprise connections** in Fuxam, and the **email domains** that decide who uses each connection.

- An **enterprise connection** is the trust relationship between Fuxam and one identity provider, established over SAML.
- Each connection owns a set of **email domains**. When someone enters an email on a matching domain, Fuxam sends them to that connection's provider to sign in.
- People whose email does not match any connection continue to sign in with a Fuxam password.
- Optionally, you can **force SSO on your institution subdomain** so that everyone visiting your dedicated Fuxam address is sent straight to your provider.

## Key concepts

| Term | Meaning |
|---|---|
| **Identity provider (IdP)** | The external service that authenticates your people — for example, Microsoft Entra ID, Okta, or Google Workspace. |
| **Enterprise connection** | A configured SSO link between Fuxam and one identity provider, based on SAML. |
| **Service provider (SP)** | Fuxam's side of the SAML relationship. The IdP setup guide gives you the SP values (such as the ACS URL and entity ID) your provider needs. |
| **Email domain** | The part of an address after the @ (for example, `university.edu`). Domains attached to a connection route matching users to that connection. |
| **Active / inactive connection** | Only an **active** connection routes real sign-ins. A new connection stays inactive until setup is complete and you activate it. |
| **Force subdomain SSO** | An institution-wide option that sends everyone on your Fuxam subdomain to SSO by default. |
| **Auto-sync new users** | A per-connection option that adds a new member's email domain to the connection automatically as people join. |

## Where to start

A typical rollout runs in this order:

1. Gather your identity provider's SAML details (or the metadata URL/file).
2. [Set up an SSO connection](/docs/fuxam-web/settings/single-sign-on/set-up-sso) — create it, exchange configuration with your provider, and activate it.
3. [Manage its email domains](/docs/fuxam-web/settings/single-sign-on/manage-email-domains) — add the domains that should use it, sync domains from your existing users, and decide whether to keep them in sync automatically.
4. Test a sign-in with an account on a matching domain before rolling out to everyone.

:::tip
Start with one connection and one domain, confirm a real sign-in works, then add remaining domains. It is far easier to diagnose SSO with a single known-good path than with several connections at once.
:::

## In this section

**[Set up an SSO connection](/docs/fuxam-web/settings/single-sign-on/set-up-sso)**

Create an enterprise connection, exchange SAML configuration with your identity provider, and activate it.

**[Manage email domains](/docs/fuxam-web/settings/single-sign-on/manage-email-domains)**

Add and remove domains, sync them from existing users, handle public-domain limits, and auto-sync new users.

## Related pages

- [Roles and permissions](/docs/fuxam-web/base/user-management/roles-and-permissions) — the access right that controls who can manage SSO.
- [Create a user](/docs/fuxam-web/base/user-management/create-a-user) — how new members are added, which can also feed domain auto-sync.
- [Settings overview](/docs/fuxam-web/settings) — the other institution-wide settings SSO sits alongside.
