Menu
Articles in this section
- Permissions & Users: FAQ
- SSO/SAML: FAQ
- Simple vs Advanced Permissions
- Advanced Permissions Guide
- Advanced Permissions: Organization-Wide Sharing
- Advanced Permissions: Profiles
- Advanced Permissions: Roles
- Advanced Permissions: Sharing Rules
- How to create a team
- Granting or removing export permissions
SSO/SAML: FAQ
Short answers about single sign-on. Setup is on SSO / SAML, with Okta and OneLogin walkthroughs on SSO/SAML: additional providers.
Which plans include SSO?
SAML and SCIM are Enterprise only.
Do I need SAML to use the SSO feature with O365?
No. SAML does not need to be enabled for users to sign in with their Microsoft credentials. You only need SAML for features such as multi-factor authentication and integration with Okta, PingIdentity, OneLogin, ADFS, and similar providers. Microsoft SSO and SAML SSO are different things and are easily conflated.
Which identity providers are supported?
Any SAML 2.0 identity provider, such as OneLogin, Okta, Ping Identity, Google Workspace, or Microsoft Entra ID. See SAML.
Does SAML work on the Insightly Mobile App?
No, not at this time. Neither SAML nor SCIM is supported on the mobile application.
Can users start the sign-in from Insightly’s login page?
No. Insightly supports IdP-initiated SAML only, so the sign-in has to start at the identity provider. See SAML.
I enabled SAML but users can still sign in with a password. Why?
Enabling SAML leaves the old route open. Enforcement is a separate checkbox. See Setting up SAML.
What certificate does Insightly need?
An X.509 certificate with an embedded public key, generated with DSA or RSA. Uploading metadata without the right certificate embedded causes an error. See Setting up SAML.
What is SCIM and do I need it?
SCIM provisions and manages Insightly users automatically from your identity provider. It is optional, and it depends on SAML being set up first. See SCIM.
Does the user’s Insightly email have to match their identity provider email?
Yes. The email address used in Insightly has to match the one at the identity provider, or the connection will not resolve to the right account.
I removed a user from Azure AD. Why can they still sign in?
Removing a user from the identity provider does not remove their Insightly access. Delete them from both systems. See Azure AD and Entra ID.
Does SSO work in a sandbox?
No. SSO users need an admin to set them up with a standard login to access a sandbox. See Sandboxes.
Related to