Skip to content →
Log in

Authentication

Configure SSO, SCIM provisioning, and session policy.

Connect an identity provider#

  1. Open Settings → Authentication → Single Sign-On.
  2. Choose Entra ID, Okta, Google Workspace, custom OIDC, or custom SAML.
  3. Copy the Console-generated callback or service-provider values into the provider.
  4. Add and verify the organization’s email domain.
  5. Test with a non-owner account.
  6. Enable the provider, then choose optional or required SSO under Policies.

Do not require SSO until a provider and verified domain work. Keep a tested recovery path during rollout.

Provision users#

Under Provisioning, create a scoped SCIM token, copy it once into the identity provider, and revoke it when rotated. Use groups as access-policy subjects where possible.

Session lifetime, idle timeout, and just-in-time provisioning are configured under Policies. Device authorization still uses browser authentication; Linux starts it with pulsectl login, while macOS starts it in the PulseHA app.

Authentication events are investigated under Security → Audit, not a separate Settings audit product.