Authentication
Configure SSO, SCIM provisioning, and session policy.
Connect an identity provider#
- Open Settings → Authentication → Single Sign-On.
- Choose Entra ID, Okta, Google Workspace, custom OIDC, or custom SAML.
- Copy the Console-generated callback or service-provider values into the provider.
- Add and verify the organization’s email domain.
- Test with a non-owner account.
- Enable the provider, then choose optional or required SSO under Policies.
Do not require SSO until a provider and verified domain work. Keep a tested recovery path during rollout.
Provision users#
Under Provisioning, create a scoped SCIM token, copy it once into the identity provider, and revoke it when rotated. Use groups as access-policy subjects where possible.
Session lifetime, idle timeout, and just-in-time provisioning are configured under Policies. Device authorization still uses browser authentication; Linux starts it with pulsectl login, while macOS starts it in the PulseHA app.
Authentication events are investigated under Security → Audit, not a separate Settings audit product.