# How to set up Single Sign-On (SSO) for your team in Genially

> Single SignOn or SSO is an authentication method that simplifies your teams access to Genially and strengthens security  In this tutorial youll learn how

Source: https://help.genially.com/en_us/how-to-set-up-single-sign-on-sso-in-genially-HkSIzRgJbl

Last updated: 2026-01-16T09:00:31.494Z

**Single Sign-On**, or **SSO**, is an authentication method that simplifies your team’s access to Genially and strengthens security.

In this tutorial, you’ll learn how to configure SSO based on SAML 2.0 for your team.

This feature is available for teams with **Enterprise and Campus** plans, and only users with the **Owner role** can configure it. Here’s how to set it up.

If you don’t have a technical background, you may need to contact the **IT administrator** of your company or organization.

  

## Prerequisites

To enable SSO, you’ll need:

*   At least one **verified team domain**. Only domains with Verified status can be used. Check out our tutorial on [how to verify your domain.](https://help.genially.com/en_us/how-to-verify-your-domain-to-enable-sso-genially-S19vxol1be)
*   A **SAML 2.0–compatible IdP**(Identity Provider) such as Azure AD, EntraID, Google Workspace, Okta, or ADFS, and the following details:

*   Entity ID (the IdP’s unique identifier)
*   Single Sign-On URL (Login URL)
*   Single Logout URL (Logout URL)
*   X.509 digital certificate encoded in Base64
*   Email attribute (optional, if your IdP doesn’t use NameID as the email)

  

In your IdP, you’ll need to **create and configure the Genially app** before proceeding. Here are a couple of tutorials for the most common IDPs:

*   [Microsoft Entra ID (Azure AD)](https://help.genially.com/en_us/set-up-single-sign-on-sso-with-microsoft-entra-id-azure-ad-for-genially-rkjv8k5xWg)
*   [Okta](https://help.genially.com/en_us/configure-single-sign-on-sso-with-okta-for-genially-HkM0IwUrWx)

  

To do so, you’ll need the **Genially metadata**, which you can access [here](https://auth.genially.com/saml/sp/metadata). Please share this metadata with your IT team.

  

## How to set up SSO login in Genially

1.  From the sidebar menu, click your team icon in the top-left corner and select **Settings > SSO configuration**.

*   If your plan doesn’t include SSO, you’ll see a message with a link to Genially’s plan page.
*   If you don’t have permissions, you’ll receive a warning about that.
*   If your plan includes SSO and you have permissions but don’t see the SSO section, contact your account manager. Domain verification might need to be enabled in your dashboard.

  

2.  **Click Add configuration**.

  

3.  Complete the **form**. We need this information to establish communication between the two systems. You can do this in two ways:

1\. Your IdP might provide an .xml file that automatically imports the data and fills in the form. If that’s the case, click **Choose file** in the first section of the form, and the fields will populate automatically. If you choose this option, you’ll only need to manually configure the last two fields: **Allow any login method** and **Enable configuration**.

2\. You can also manually enter your IdP’s information. The fields are:

*   **Name**: Internal label to identify the configuration (max 25 characters).
*   **Domain(s)**: The email domains you’ve enabled for SSO login. Select one or more domains with Verified status. A domain can only be used in one SSO configuration.
*   **Entity ID**: Your IdP’s identifier.
*   **Login URL**: EntryPoint URL for sign-in.
*   **Logout URL**: EntryPoint URL for sign-out.
*   **Certificate**: Paste your IdP’s Base64-encoded X.509 certificate.
*   **Email attribute (optional)**: The key that contains the user’s email if you don’t use NameID.
*   **Allow any login method**: When enabled, members can sign in via SSO or traditional methods (username and password). When disabled, access is restricted to SSO, and users can only log in through your organization’s identity provider.
*   **Enable configuration**: Check this box to enable the configuration after saving.

  

4.  Click **Save** to create the configuration.

  

### Important notes

*   The login and logout URLs must be in a valid format (e.g., [https://idp.example.com/sso/login](https://idp.example.com/sso/login)). The form will alert you if the format is invalid.
*   You can only select **verified domains**. If your domain isn’t listed, verify it first following [this tutorial](https://help.genially.com/en_us/how-to-verify-your-domain-to-enable-sso-genially-S19vxol1be).
*   If a domain is already used in another SSO configuration, the system will display an error showing which domain is duplicated.

  

## Managing existing configurations

In the Team **Settings > SSO section**, you can manage your existing configurations. These are your options:

*   **View status**: Each card shows whether the configuration is Enabled or Disabled, and you can toggle **Allow any login method**.
*   **Edit**: Click the edit icon to update information, change domains, activate or deactivate configurations, or modify settings. When you change domains, the system will check that they’re verified and not duplicated.
*   **Enable/Disable**: You can change a configuration’s status at any time. Disabling it won’t delete it; it simply pauses the configuration.
*   **Delete**: Click the trash icon and then **Confirm** to finalize deletion. This action is permanent.

  

## Multiple domains and configurations

*   You can associate multiple verified domains with a single SSO configuration.
*   You can create multiple SSO configurations for your team, as long as no domains are repeated.
*   Currently, only the SAML 2.0 protocol is supported. If your provider uses a different protocol, please contact your Genially account manager.

  

## Best practices

Here are some recommendations to ensure SSO runs smoothly for your team:

*   Request an updated X.509 certificate from your IdP, and plan renewals in advance.
*   Verify that your login and logout URLs are accessible from the internet and match those published by your IdP.
*   Clearly define the email attribute if your IdP doesn’t use NameID as the email.
*   Enable **Allow any login method** during your initial rollout to ease the transition, and later adjust your policy if needed.

  

## Troubleshooting

*   **I don’t see any domains to select**

Make sure your team’s domain is verified. Only domains with **Verified** status will appear.

*   **Error: “Domain already in use”**

That domain is already associated with another SSO configuration. Edit or delete the existing one, or use a different domain.

*   **Error: “Invalid URL”**

Check that your URLs include http/https and are valid.

*   **Can’t log in via SSO**

*   Check the Entity ID, URLs, and certificate.
*   Make sure the email attribute matches the mapping in your IdP.
*   Verify that the configuration is enabled.

  

## Help and support

If you’re having trouble with domain verification or SSO setup, or need extra assistance, you can contact your Genially account manager.
