# Single Sign-On (SSO)

**Category:** [Security & Access](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/categories/security-access)
**Updated:** 2026-08-19

## What is SSO?

SSO lets your team log in to TotalCtrl using your existing identity provider (Okta, Azure AD, Google Workspace, or any SAML 2.0-compatible provider) without maintaining a separate password.

## Supported protocols

  
- SAML 2.0 and OIDC (OAuth 2.0)

## Configuring SSO

  
- Go to **Settings → Security → SSO**.
  
- Select your protocol (SAML or OIDC).
  
- Enter the metadata from your IdP.
  
- Copy the TotalCtrl ACS URL / Callback URL and configure it in your IdP.
  
- Test the connection by clicking **Test SSO**.
  
- Optionally enable **Enforce SSO-only login**.

## Auto-provisioning

When a user logs in via SSO for the first time, TotalCtrl automatically creates their account and assigns the configured default role.

---

## Related Articles

- [Setting Up SSO with Okta or a Custom OIDC Provider](https://help.totalctrl.app/en-US/articles/setting-up-sso-with-okta-or-a-custom-oidc-provider)
- [Two-Factor Authentication (2FA)](https://help.totalctrl.app/en-US/articles/two-factor-authentication-2fa)
- [Setting Up SSO with Google Workspace](https://help.totalctrl.app/en-US/articles/setting-up-sso-with-google-workspace)
- [API Tokens](https://help.totalctrl.app/en-US/articles/api-tokens)
- [Setting Up SSO with Microsoft / Azure AD](https://help.totalctrl.app/en-US/articles/setting-up-sso-with-microsoft-azure-ad)

---
[← Back to TotalCtrl Help Center](https://help.totalctrl.app/en-US/)