March 2026
SAML SSO: Enterprise Single Sign-On, Self-Served
Enterprise teams shouldn’t have to manage a separate set of StackOne passwords, invite every user by hand, and remember to remove them one by one when they leave. That manual lifecycle creates a real offboarding gap: a departed employee can keep dashboard access if the removal step is missed.
StackOne now supports enterprise Single Sign-On through SAML 2.0. Admins connect their existing Identity Provider once in Organization Settings, and users sign in with their corporate credentials. Because it’s built on the SAML 2.0 standard, it works with any compatible identity provider, such as Okta, Microsoft Entra ID, OneLogin, or Ping.
What’s new
- SAML 2.0 single sign-on - Full SP-initiated authentication flow compatible with any SAML 2.0 IdP, so one integration covers Okta, Entra ID, OneLogin, Ping, and beyond with no vendor lock-in.
- Self-service configuration - IT admins set up SSO end-to-end in Organization Settings in about 15 minutes. Copy the ACS URL and Entity ID into your IdP, paste the IdP metadata and certificate back, test, and enable, with no StackOne team involvement required.
- Centralized access control - Authentication runs through your IdP on every login. Remove a user from the StackOne app in your IdP and their next login attempt is rejected, closing the offboarding gap.
- Mandatory SSO enforcement - An org-level toggle requires all users to authenticate via SSO and blocks email and password fallback, so access is governed entirely by your IdP.
Follow the SSO setup guide for the full walkthrough, including a step-by-step Okta example.