Supported SSO Providers
Google Workspace
OAuth 2.0 / OpenID Connect. Easiest setup for Google Workspace organizations.
Microsoft Entra ID
OAuth 2.0 / OpenID Connect. For organizations using Azure AD / Entra ID.
Okta
SAML 2.0. Enterprise-grade identity management with granular access control.
Custom SAML
SAML 2.0. For any SAML-compatible identity provider (OneLogin, JumpCloud, PingOne, etc.).
SSO Enforcement
After configuring SSO, you can choose how strictly it is enforced:| Mode | Description |
|---|---|
| Optional | Users can sign in via SSO or email/password. Useful during rollout. |
| Required | All users must sign in via SSO. Email/password login is disabled. |
SSO and User Provisioning
SSO handles authentication (verifying identity) but not provisioning (creating accounts). Users must still be invited to your LowerPlane organization before they can sign in via SSO. The typical workflow:- Admin invites a user by email in Settings > Users.
- The user clicks the invitation link and creates their account.
- On subsequent visits, the user signs in via SSO.
Compliance Benefits
SSO configuration satisfies authentication controls across frameworks:| Framework | Controls |
|---|---|
| ISO 27001 | A.9.4.2 (Secure log-on procedures) |
| SOC 2 | CC6.1 (Logical access security) |
| HIPAA | 164.312(d) (Person or entity authentication) |
| GDPR | Article 32 (Appropriate technical measures) |
| PCI-DSS | 8.1 (Identify and authenticate access) |