Menu
Articles in this section
SSO / SAML
SAML gives users a single sign-on into Insightly through an identity provider. SCIM automates provisioning those users from the same provider. Both are Enterprise only, and SCIM depends on SAML.
⚠️ Neither SAML nor SCIM is supported on the Insightly mobile application.
On this page:
SAML
Security Assertion Markup Language is the single sign-on standard for enterprise cloud applications. Administrators manage access from one place and users reach multiple applications through one login at an identity provider such as OneLogin, Okta, Ping Identity, Google Workspace, or Microsoft.
Insightly supports SAML 2.0 as a Service Provider.
⚠️ Insightly supports IdP-initiated SAML 2.0 only. SP-initiated SAML is not supported, so a flow that starts at Insightly rather than at the identity provider will not work.
⚠️ Certificate requirements are specific. The verification certificate must be X.509 format with an embedded public key, generated with either the DSA or RSA algorithm. Nothing else is accepted.
Setting up SAML
- Have an account with an identity provider.
- Add your users to Insightly and have them complete registration. The email address used in Insightly has to match the user’s email address at the identity provider. Skip this step if you are going to use SCIM.
- Go to System Settings > Security > SAML and SCIM and check Enable SAML Sign-on.
- Copy the URL from Sign-on Page URL. In the identity provider, create a SAML app for Insightly and paste that URL into the relevant field.
- Enter the System Admin email address for the Insightly account, then download the identity provider’s public key or certificate file.
- Back in System Settings > Security > SAML & SCIM, upload either the certificate or the XML metadata file. Only one is needed.
- To require SSO, check Enforce SAML Login and click Save.
⚠️ Uploading metadata without the right certificate embedded causes an error. If you upload the XML metadata file rather than the certificate, confirm the correct certificate is inside it.
ℹ️ SAML enabled but not enforced leaves the old route open, and users can keep signing in without SSO. Enforcement is the checkbox, not the integration.
SCIM
System for Cross Domain Identity Management automates moving user identity information between systems. It lets administrators provision and manage Insightly users centrally from an identity provider such as Okta or Azure Active Directory.
Insightly supports the /Users and /Schemas endpoints of SCIM 2.0. Batch operations are not supported.
Setting up SCIM
- Go to System Settings > Security > SAML and SCIM and confirm SAML is already enabled and configured. SCIM cannot be set up without it.
- Check Enable SCIM Provisioning and click Save. This generates the SCIM token and reveals the SCIM URL.
- After the page reloads, copy the SCIM Token and SCIM URL using the clipboard buttons beside each field.
Regenerate issues a new token and invalidates every previous one. The new token saves instantly, so Save is not needed afterwards.
⚠️ SCIM does not assign product licenses. Users provisioned through SCIM arrive without licenses, and an administrator has to assign them by hand before those people can work.
To assign licenses: go to System Settings > Users > User List, open the three-dot menu for the user, select Edit User Settings, enable the checkboxes in Product User Licenses, and click Save User Details.
Supported operations
| Operation | Description | Notes |
|---|---|---|
GET /Users |
Gets a list of users | Returns both active and inactive users. Paging per SCIM spec. |
GET /Users/{id} |
Gets a single user | Returns the user whether active or inactive |
GET /Users?filter=userName eq “user@example.com” |
Gets users by query | Returns active and inactive users matching the filter. Only the userName eq filter is supported. |
POST /Users |
Creates a user | |
PUT /Users/{id} |
Updates a user | |
PATCH /Users/{id} |
Updates only the fields in the request | Only the replace operation is supported. |
DELETE /Users/{id} |
Deactivates a user | Insightly does not hard delete users. Equivalent to setting active=false. |
GET /Schemas |
Returns the attributes Insightly supports |
User attribute mappings
| SCIM attribute | Insightly field | Notes |
|---|---|---|
| id (read only) | User.USER_ID | Insightly-generated unique identifier |
| userName | User.EMAIL_ADDRESS | |
| meta.resourceType (read only) | “User” | |
| meta.created (read only) | User.DATE_CREATED_UTC | Insightly-generated |
| meta.lastModified (read only) | User.DATE_UPDATED_UTC | Insightly-generated |
| active | User.ACTIVE | Editable, but set to true when creating a user |
| name.givenName | User.FIRST_NAME | |
| name.familyName | User.LAST_NAME | |
| emails (read only) | User.EMAIL_ADDRESS | A single address with type=work |
Azure AD and Entra ID: SAML and SCIM
Step 1: add the enterprise application
- Go to the Azure Portal and select New Application.
- Search for Insightly SAML.
- Select it from the results and click Create.
Adding a New Enterprise Application in Azure AD
Step 2: configure SAML SSO
- In the Enterprise Application menu, go to Single sign-on and choose SAML.
- Click Edit next to Basic SAML Configuration.
- Copy the Insightly SAML login URL, either from System Settings > Security > SAML and SCIM (the Sign-in page URL field) or from the SAML settings page in your Insightly instance.
- Paste that URL into both the Identifier (Entity ID) and the Reply URL (Assertion Consumer Service URL) fields.
- Download the SAML certificate from Azure, in Base64 or Federation Metadata XML. Base64 is recommended.
- On Insightly’s SAML settings page, upload either the certificate or the metadata. Only one is needed.
- Select Enforce SAML Login and click Save.
Once enforced, sign in to Insightly through https://myapps.microsoft.com/.
Selecting SAML Single Sign-On Method in Azure
SAML Certificate Download Options in Azure AD
Step 3: configure SCIM
In Insightly, check Enable SCIM Provisioning on the SAML configuration page and press Save, which generates the auth token and reveals the SCIM endpoint.
In Azure:
- Go to the Provisioning section for the app and click Get Started.
- Set Provisioning Mode to Automatic.
- Paste the Tenant URL and Secret Token from Insightly into the matching fields.
- Click Test Connection. Success shows a notification in the top-right corner.
- Click Save, then Start Provisioning.
SCIM Provisioning Setup in Insightly CRM
Successful SAML Provisioning Connection Test
Step 4: assign users
Assign users from the Users and Groups section in Azure.
Assigning Users to Insightly SAML Application
ℹ️ Provisioning runs on a schedule, so new users do not appear in Insightly immediately. Provision on demand triggers it manually.
Azure AD SSO without SCIM
The simpler Insightly SSO application gives Azure Active Directory users one-click access without SAML configuration.
- Log in to the Azure portal and select Azure Active Directory.
- Click Enterprise applications, then All applications under Manage.
- Click New application, then All under Categories.
- Search for and select Insightly.
- Click Sign up for Insightly to log in and grant permissions.
- Close the panels back to All applications, then search for and click Insightly.
- Select Users and groups, click Add user, then Users.
- Check the users who will use Insightly and click Select, then Assign.
Assigned users reach Insightly from their Azure AD access panel at http://myapps.microsoft.com or the Office 365 portal, clicking the Insightly icon to sign in without entering credentials.
Insightly App in Microsoft Office 365 Launcher
⚠️ Each user’s Insightly login email must match their Microsoft login email, or the connection will not resolve to the right account.
⚠️ Removing a user takes two steps. Users can still sign in to Insightly directly, so removing them from Azure AD alone does not remove their access. Delete them from both systems.
Related to