Organization settings

Manage single sign-on (SSO) login settings

Learn how to manage SSO login settings for your organization to control how users access the platform and ensure secure, streamlined authentication across your team.

Last updated: August 10, 2026

What does it mean to manage SSO login settings?

When you manage SSO login settings, you control how your team logs in to Mitti once single sign-on is set up for your organization. You can enforce SSO for everyone, allow users to choose between SSO and their password, or enforce it only for specific email domains. This allows you to match your organization's access requirements without limiting how your team gets to work.

Manage SSO login type

  1. Log in to the web app (opens in new tab).

  2. Click your organization name on the lower-left corner of the page and select Organization settings.

  3. Select Security at the top of the page.

  4. Click Edit in the "Single sign-on (SSO)" box.

  5. Click the dropdown menu for "Login type" and select one of the options accordingly. Manage SSO login settings via the web app.

    • Allow SSO and native login: Users can log in with either their SSO account or their Mitti password.

    • Allow SSO login only: Users can only log in with their SSO account. Requires Enterprise Plan.

    • SSO enforced for named domains: Users log in with SSO or their password depending on their email domain. Requires Enterprise Plan.

  6. Click Save changes.

Turn IdP-initiated login on or off

IdP-initiated login controls whether users can start their Mitti session from your identity provider's portal instead of logging in through Mitti directly. Some identity providers don't support this method.

  1. Log in to the web app (opens in new tab).

  2. Click your organization name on the lower-left corner of the page and select Organization settings.

  3. Select Security on the top of the page.

  4. Click Edit in the "Single sign-on (SSO)" box.

  5. Turn "IdP-initiated login" on or off accordingly. Turn IdP-initiated login on or off via the web app.

  6. Click Save changes.

We advise against turning "IdP-initiated login" on as it may pose security risks.

Frequently asked questions

Was this page helpful?