SSO / Single Sign-On
The SSO module connects Notory to your identity provider, per tenant - via SAML2 or OIDC/OAuth2. New users can be provisioned automatically via JIT provisioning, and groups or claims from the identity provider can be mapped straight onto Notory roles. The regular password + 2FA (TOTP) login stays in place alongside it - SSO is an additional, per-tenant login path, not a forced replacement.
SAML2 & OIDC per tenant
Each tenant configures its own identity provider connection - via SAML2 or via OIDC/OAuth2. That lets Notory plug into Entra ID/Azure AD, Okta, Keycloak, or other identity providers.
JIT provisioning with an allow/deny toggle
A Notory user is created automatically on first SSO login, instead of every account needing to be pre-created by hand. An explicit per-tenant toggle allows or denies JIT provisioning.
Group/role mapping
SSO groups and claims from the identity provider can be mapped onto Notory roles. Role assignment stays centrally controlled by the identity provider instead of being managed twice.
Not a forced replacement
SSO complements the existing password + 2FA (TOTP) login rather than replacing it. Each tenant decides for itself whether and how SSO is used as an additional login path.
Example: a school district with an existing Entra ID tenant
A school district connects Notory to its existing Entra ID tenant via OIDC, instead of managing credentials twice. The "IT-Admins" AD group is mapped to the Notory admin role, and everyone else gets a standard role automatically. New staff joining the IT department get a Notory account with the right role auto-provisioned on their first SSO login - no manual account creation by the administration required.
Related topics and modules
Complementing the SSO module:
Questions on SSO / Single Sign-On
What does the SSO module cover and which protocols are supported?
The SSO module lets each tenant connect its own identity provider - via SAML2 or via OIDC/OAuth2. That means Notory can plug into Entra ID/Azure AD, Okta, Keycloak, or other common identity providers instead of managing yet another separate login.
What is JIT provisioning, and can it be turned off?
Just-in-time provisioning automatically creates a Notory user account on a person's first SSO login, so admins don't have to pre-create every account by hand. Each tenant has its own allow/deny toggle for JIT provisioning and can disable it whenever needed.
Which plan includes SSO?
SSO is included from the Pro plan onward (Pro, Elite and Enterprise). It is not available on Starter or Basic.
One less login to manage
SSO is included from Pro - connect Notory to your existing identity provider and let new accounts provision themselves. Check pricing or request a live demo.