SAML Single Sign On

Enable Single Sign-On (SSO) in Fillout to streamline user authentication and access management. This article will guide you through the setup process to enable SSO through various providers like Okta, Azure AD, and all SAML providers.

SAML is available on the Enterprise Plan.
SAML is available on the Enterprise Plan.

Pre-requisites

  • You must have the 'Admin' role in your Fillout team

Setting up SSO

  1. Navigate to your Fillout Dashboard and click on Settings. Find the SSO section.
  1. Click on Configure SSO. You will be guided through the setup process.
  1. Provide the required information depending on your identity provider (IdP) such as Okta, Azure AD, etc.
  1. Save the changes.
Note: At this point, you can set the default roles for newly provisioned users.

User Deprovisioning

Fillout is SCIM compliant. Therefore, when a user is removed from your SAML provider, they are automatically offboarded from Fillout.

How to Log in Using SSO

Once SSO is configured, your team members can log in by clicking on "Login with SSO" on the Fillout login page and entering their company email.
 
notion image

Enforcing SSO

You can enforce SSO for additional security measures. To do this:
  1. Go to the SSO tab under Settings.
  1. Locate 'Enforce SSO' and enable it.
 
You can only enforce SAML SSO for a team if your current session was authenticated with SAML SSO. This ensures that your configuration is working properly before tightening access to your team information, this prevents loss of access to the team.