Single sign-on (SSO)
Implement secure authentication for your team.
Last updated
Was this helpful?
Implement secure authentication for your team.
Last updated
Was this helpful?
Felt provides Single Sign-On (SSO) functionality for Enterprise workspaces. This enables IT to easily manage access through a single authentication source. Felt’s SSO is built upon the SAML 2.0 standard.
This feature is only available on the Enterprise plan. Contact sales to upgrade.
Your workspace is on the Enterprise Plan
You are an admin in your Felt workspace
You have an Identity Provider (IdP) that supports SAML 2.0
You are an admin in your Identity Provider
Okta
Entra
OneLogin
JumpCloud
Duo
Rippling
Generic SAML 2.0 capable provider
Enable SSO on for your Enterprise workspace
Configure the SAML connection between Felt and your IdP
You’ll share 3 fields from your IdP with Felt
You’ll share 3 fields from Felt with your IdP
You’ll configure 3 SAML attributes to be shared with Felt
Configure your Felt Enterprise SSO settings
Navigate to your Felt workspace, click “Settings”, then “Workspace”
Click “Enable SSO for yourdomain.com” under “Enterprise SSO”
You’ll be asked to confirm that you have admin access inside your IdP. Click “Configure SAML”
In the new tab that has been opened, select your Identity Provider
You will be now guided through a series of steps to configure the SAML connection between Felt and your IdP. These steps may vary between Identity Providers, so follow the details provided in the guide.
Create a SAML app inside your IdP
Provide the 3 requested fields from your IdP
SAML 2.0 Endpoint
Issuer URL / Entity ID
Certificate
Enter the 3 provided fields into your IdP
ACS URL
ACS URL Validator
Audience (EntityID)
Configure the 3 required SAML attributes
email
first_name
last_name
You can skip Step 5, user role configuration is not used
Click “Finish”
Click “Test Connection” to confirm that the connection was successful
You may need to add your own user to the new SAML application inside your Identity Provider for this test to succeed.
Click “Finish & go live”
Close the configuration tab and go back to your Felt workspace settings
You may now configure your Felt Enterprise SSO settings
“Require SSO login”
This setting requires that all users on your email domain must login using SSO
Users will no longer be able to login using a password if they already had one
Admin users are always exempt from this restriction
“Automatically invite new users”
When this setting is on, new users that login to your email domain using SSO will be automatically invited to your Workspace.
If you reach your member/editor limit, additional logins will create Felt user accounts, but they won’t be added to your Workspace.
They will be invited at the “Default permission level” you have set in the “Joining the workspace” section
Inside your IdP, assign users you wish to have Felt access to the new SAML application that was created. Only users you assign will be able to login to Felt.