Skip to main content

SSO Connections

Organization admins can configure Single Sign-On (SSO) from the Admin section of the Tenzo app.
  • Navigate to Admin > Organization & Users > SSO Settings.
This page lists all configured SSO connections for your organization. When an SSO connection is active, users in the organization must sign in to Tenzo with their identity provider. Email and password sign-in is turned off for everyone except people an admin has explicitly allowed on the Manage Users page.
SSO connections page showing configured identity providers

Admin > Organization & Users > SSO Settings

Creating a New SSO Connection

To add a new SSO connection:
  1. Go to Admin > Organization & Users > SSO Settings.
  2. Click New connection.
  3. Enter a Display Name that will help admins recognize the connection (for example, “Okta - Production”).
  4. Follow the guided setup flow on the SSO configuration page. The UI will walk you through copying any values needed into your identity provider and pasting the provider details back into Tenzo.
  5. Save the connection once the setup flow indicates that configuration is complete.
After saving, the connection will appear in the SSO list with its IdP, status, and available actions.

Testing and Enabling SSO

After creating a connection, use a test account from your identity provider to sign in via the SSO option on the Tenzo login page and confirm that you can successfully access your workspace. Once verified, users in your organization will enter their email on the Tenzo login page and be routed into SSO automatically, unless an admin has allowed that person to use email and password.

Organizations With Multiple SSO Connections

Some organizations configure more than one active SSO connection — for example, separate identity providers for different business units or subsidiaries under the same Tenzo organization.
  • If your organization has exactly one active SSO connection, users enter their email and see a Continue with SSO button that sends them directly to that identity provider.
  • If your organization has more than one active SSO connection, users instead see a connection picker as soon as they enter their email — before any “Continue with SSO” button appears. The picker lists each active connection by its Display Name and IdP; the user selects the correct one for their team, then clicks Continue with SSO to proceed to that identity provider.
Because the picker is keyed off the connection’s Display Name, use a clear, recognizable name (for example, “Acme Corp - Okta” rather than “Connection 1”) when creating connections for organizations that will have more than one.

Managing Existing Connections

From the SSO Settings page you can:
  • Search for a specific SSO connection by display name.
  • View the associated IdP and status.
  • Use the actions menu to update or disable a connection when needed.
Disabling a connection prevents new logins via that IdP while keeping the configuration available for future reactivation.