How do I enforce SAML SSO for my company's Tilt account?
Connect your identity provider and enforce SAML SSO — from Okta and Azure setup to going live.
Quick answer
You can enable SAML Single Sign On enforcement in Org Settings → Security. Before turning it on, click Configuration Setup to connect your identity provider.
Who this applies to / Prerequisites
- You are an HR admin at a Tilt customer.
- Your company uses a SAML-compliant identity provider (Okta, Azure, or another SAML IdP).
- Employees retain access to your identity provider during leave (or your company can configure the IdP to allow Tilt-only access during leave).
Steps
- Log into Tilt as an HR admin.
- Click Org Settings in the left-hand navigation.
- Click Security.
- Enable SAML Single Sign On..
- Complete the identity provider setup:
- For Okta: see Set Up the Okta Integration.
- For Azure: see Set Up SSO with Azure.
- For any other SAML-compliant IdP: use the Configuration Setup link inside the SAML Single Sign On tile and enter your IdP's SAML values.
- Work with your Implementation Guide or Customer Success Manager if you need help with the IdP configuration.
What if it doesn't work
- If the toggle is grayed out or unavailable, contact your Customer Success Manager to confirm SAML SSO is enabled for your account.
- If employees can't log in after enforcement, verify their work email in Tilt exactly matches their email in your identity provider.
Limits and exceptions
- If your company revokes employee access to your identity provider during leave, employees will LOSE access to Tilt during leave. Consider 2FA instead.
- Once SAML SSO is enforced, employees cannot use email and password to log in. They must go through your identity provider.
- You cannot enforce SAML SSO and Google SSO at the same time. Choose one.
Related questions
- Set Up the Okta Integration
- Set Up SSO with Azure
- Which login method should I choose for my company's Tilt account?
- How do I switch from one enforced login method to another in Tilt?