SAML and OIDC SSO with Okta, Google Workspace, Microsoft Entra, and any standards-compliant IdP. Configure in Settings → Security → SSO, test with one user, then enforce workspace-wide.
Setup flow
Settings → Security → SSO → pick provider. turgo shows the exact values for your IdP config (ACS URL, entity ID / redirect URI, required claims); paste the IdP's metadata URL or cert back. Guided per-provider instructions inline.
Test before enforcing
Enable in test mode: SSO works but password login stays available. Log in via SSO with one account, verify attributes map (email, name, groups if used), then flip Enforce.
Enforcement and break-glass
Enforce disables password login for everyone except designated break-glass admins (keep two, hardware-2FA'd) — so an IdP outage doesn't lock the whole org out.
Group mapping
Optionally map IdP groups to turgo roles and teams: membership changes in Okta/Entra propagate on next login. Full lifecycle automation is SCIM's job (see SCIM provisioning).