<!-- LLM_VERSION_INFO
FORMAT: text/markdown
CONTENT_TYPE: article
ORIGINAL_URL: https://jam.dev/docs/product-features/single-sign-on
ALTERNATE_VERSION: docs/product-features/single-sign-on/index.html (text/html)
EXTRACTION_DATE: 2026-04-17T03:46:23.715Z

This is the markdown version with text-only content (images converted to alt-text).
For rich formatting with images, request the HTML version at: docs/product-features/single-sign-on/index.html
-->

Available to workspaces on our [Enterprisearrow-up-right](/content/pricing/index.html) plans.

### [hashtag](/content/docs/administration/sso#overview/index.html)    Overview

Connect your identity provider to Jam for streamlined authentication and automated team management. Your team gets secure, centralized access control while you eliminate manual user provisioning overhead.

### [hashtag](/content/docs/administration/sso#how-it-works/index.html)    How It Works

**SSO (Single Sign-On):** Connects your identity provider to Jam for authentication. Team members log in using their corporate credentials instead of separate Jam passwords.

**Directory Sync:** Automatically syncs user changes from your identity provider to Jam. When you add, remove, or modify users in your IdP, those changes reflect in your Jam workspace automatically.

### [hashtag](/content/docs/administration/sso#configure/index.html)    Configure

SSO Setup

Directory Sync Setup

**Configure Single Sign-On**

1. Go to Team Settings → General → Access  
2. Click Setup next to Identity Provider  
3. Follow the step-by-step walkthrough for your IdP  
4. Complete the configuration in your identity provider

You should now see your IdP listed in the Access section. Team members can log in using SSO.

**Configure Directory Sync**

1. Go to Team Settings → General → Access  
2. Click Setup next to Active Directory  
3. Follow the step-by-step walkthrough for your IdP  
4. Select which user groups to sync (optional)

You should now see your IdP listed in the Access section. New users added to your IdP will automatically join your Jam team.

Provisioned users get the Creator role by default. You'll need to adjust roles manually in Jam settings.

#### [hashtag](/content/docs/administration/sso#user-management/index.html)    User Management

How you manage team members depends on your Directory Sync configuration:

With Directory Sync

Without Directory Sync

**Automated Management**

- User provisioning: Happens in your identity provider  
- New user notifications: Users get email notifications when provisioned  
- Role management: Handle manually in Jam team settings  
- User removal: Remove from IdP to revoke Jam access automatically  
- Group sync: Manage access via user groups in your IdP

Access the directory sync management page through Team Settings → Team → Manage Members.

**Manual Management**

- User provisioning: Add users directly in Jam team settings  
- Role management: Assign and modify roles in Jam  
- User removal: Remove users manually from team settings

All user management happens within your Jam workspace settings.

### [hashtag](/content/docs/administration/sso#faqs/index.html)    FAQs

chevron-rightCan I use SSO without Directory Sync? [hashtag](/content/docs/administration/sso#can-i-use-sso-without-directory-sync/index.html)

Yes. SSO handles authentication while Directory Sync manages user provisioning. You can enable either feature independently.

chevron-rightWhat identity providers are supported? [hashtag](/content/docs/administration/sso#what-identity-providers-are-supported/index.html)

Jam supports all major identity providers including Okta, Azure AD, Google Workspace, and SAML-compatible providers.

chevron-rightCan I map user groups to specific Jam roles? [hashtag](/content/docs/administration/sso#can-i-map-user-groups-to-specific-jam-roles/index.html)

Not automatically. While you can sync user groups from your IdP, role assignment in Jam requires manual configuration.

chevron-rightWhat happens when I remove a user from my identity provider? [hashtag](/content/docs/administration/sso#what-happens-when-i-remove-a-user-from-my-identity-provider/index.html)

With Directory Sync enabled, users automatically lose access to their Jam account when removed from your IdP.
