Single Sign-On (SSO) allows your team members to authenticate to LowerPlane using your organization’s existing identity provider. This simplifies access management, enforces your corporate authentication policies, and satisfies compliance requirements for centralized access control.

Supported SSO Providers

Google Workspace

OAuth 2.0 / OpenID Connect. Easiest setup for Google Workspace organizations.

Microsoft Entra ID

OAuth 2.0 / OpenID Connect. For organizations using Azure AD / Entra ID.

Okta

SAML 2.0. Enterprise-grade identity management with granular access control.

Custom SAML

SAML 2.0. For any SAML-compatible identity provider (OneLogin, JumpCloud, PingOne, etc.).

SSO Enforcement

After configuring SSO, you can choose how strictly it is enforced:
ModeDescription
OptionalUsers can sign in via SSO or email/password. Useful during rollout.
RequiredAll users must sign in via SSO. Email/password login is disabled.
Before enforcing SSO, verify that all team members can authenticate through your identity provider. If SSO is enforced and a user cannot authenticate, they will be locked out of LowerPlane.

SSO and User Provisioning

SSO handles authentication (verifying identity) but not provisioning (creating accounts). Users must still be invited to your LowerPlane organization before they can sign in via SSO. The typical workflow:
  1. Admin invites a user by email in Settings > Users.
  2. The user clicks the invitation link and creates their account.
  3. On subsequent visits, the user signs in via SSO.
Combine SSO with your identity provider’s access controls. Assign LowerPlane access through Okta app assignments or Azure AD enterprise applications to maintain centralized access management.

Compliance Benefits

SSO configuration satisfies authentication controls across frameworks:
FrameworkControls
ISO 27001A.9.4.2 (Secure log-on procedures)
SOC 2CC6.1 (Logical access security)
HIPAA164.312(d) (Person or entity authentication)
GDPRArticle 32 (Appropriate technical measures)
PCI-DSS8.1 (Identify and authenticate access)