Single Sign-On (SSO) with SAML
Set up SSO for your organization so your team can log in to Strike Graph with their existing company credentials
Written By Micah
Single Sign-On (SSO) allows your team to log in to Strike Graph using the same credentials they already use for other company systems. Instead of managing a separate username and password for Strike Graph, users authenticate through your organization's identity provider (IdP) and are directed straight into the platform. SSO is available as part of certain plans, or as an add-on for other plans. Implementation is handled by the Strike Graph team in coordination with your IT or security team.
How SSO works in Strike Graph
Strike Graph uses SAML (Security Assertion Markup Language) as the recommended protocol for SSO. SAML is one of the most widely supported authentication standards, and it works with most major identity providers. Once SSO is configured, the typical login flow is:
A user navigates to Strike Graph's login page (or clicks a link to Strike Graph from your internal portal).
They enter their company email address.
Strike Graph redirects them to your identity provider to authenticate.
After authenticating with their company credentials, they are redirected back to Strike Graph and signed in.
This means your team does not need to remember a separate password for Strike Graph, and your organization can enforce its own authentication policies (such as password complexity and session timeouts) at the IdP level.
Supported identity providers
Strike Graph supports SSO with any identity provider that implements the SAML 2.0 protocol. This includes providers such as:
Microsoft Entra ID (formerly Azure AD)
Okta
Google Workspace
OneLogin
JumpCloud
PingIdentity
If your identity provider supports SAML 2.0, it can almost certainly be used with Strike Graph. If you use a provider not listed above, reach out to our team and we can confirm compatibility.
What you will need to provide
To start the SSO implementation process, your IT or security team will need to provide the following information:
Sign In URL: the URL where Strike Graph should redirect users for authentication at your IdP.
x509 Signing Certificate: the certificate your IdP uses to sign SAML assertions, which Strike Graph uses to verify the authenticity of login responses.
If your IdP can export an XML metadata file that contains both of these, you can send the metadata file directly. Just let us know which field in the metadata maps to your Sign In URL.
What Strike Graph will provide
After receiving your IdP information, the Strike Graph team will configure the connection and send back the service provider metadata your IT team needs to complete setup on their end. This includes:
Entity ID: Strike Graph's unique identifier in the SAML exchange.
ACS URL (Assertion Consumer Service URL): the endpoint where your IdP sends the SAML response after authentication.
Service Provider Certificate: used by your IdP to verify communications from Strike Graph.
Implementation process
SSO setup is a collaborative process between your team and Strike Graph. Here is what to expect:
Request SSO: contact your Customer Success Manager or reach out to support through the in-app messenger to begin the process.
Exchange configuration details: provide your Sign In URL and x509 certificate (or XML metadata file). The Strike Graph team will send back service provider metadata for your IdP configuration.
Configure your IdP: your IT team adds Strike Graph as an application in your identity provider using the service provider metadata.
Test the connection: the Strike Graph team will work with you to verify that login works correctly before rolling it out to all users.
Go live: once testing is complete, SSO will be active for your organization.
The full process typically takes a few business days, depending on how quickly configuration details can be exchanged and IdP setup completed on your end.
Things to know
Existing users: if your team members already have Strike Graph accounts with username and password logins, those accounts will be linked to the SSO connection. Users will not lose access to any existing data.
New users: once SSO is active, new users invited to your Strike Graph organization will authenticate through your identity provider on their first login.SSO enforcement: after SSO is configured, your organization can choose whether to require SSO for all users or allow both SSO and password-based login. Discuss your preference with the Strike Graph team during setup.
IdP-initiated login: Strike Graph does not support IdP-initiated login (where the user clicks a link from your internal portal and is taken directly to Strike Graph).
Need help?
To get started with SSO, reach out to your Customer Success Manager or contact our support team through the in-app messenger. We will coordinate the implementation and guide you through each step.