> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sequencehq.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Single sign-on (SSO)

> Sign in to Sequence with your company identity provider

Sequence supports enterprise single sign-on (SSO), where your team can sign in to Sequence using their existing company identity.

Your identity provider (IdP) becomes the source of truth for access to Sequence: your IdP decides who can access Sequence and uses your existing MFA and login policies.

## Supported identity providers

| Identity provider | Protocols |
| - | - |
| **Okta** | SAML, OIDC |
| **Microsoft Entra ID** | SAML, OIDC |
| **Google Workspace** | SAML, OIDC |

## Signing in with SSO

Your team continues to sign in via the Sequence login page when SSO is enabled. After entering their work email, members of your organization are sent to your identity provider and land back in Sequence once authenticated.

## Setting up SSO

To enable SSO for your organization, reach out to your Sequence representative. We'll work with your IT team to connect your identity provider and configure the options below.

## Access controls

### Enforce SSO

Require everyone in your organization to sign in through your identity provider. Magic link sign-in is turned off, so access to Sequence follows your identity provider.

### Emergency access

Exempt specific members from SSO so your organization can't be locked out if your identity provider is unavailable. At least one exempt member is required before SSO can be enforced. Exemptions also suit external users, such as auditors, who aren't in your identity provider.

### Just-in-time provisioning

Off by default, so only invited users can sign in. When turned on, anyone your identity provider authorizes is added to Sequence on first sign-in with the View-only role. Admins can then adjust their access in [Roles & permissions](/users/roles-permissions).

## Changing identity providers

If a user's email stays the same, they're linked to their existing Sequence user when they first sign in through your new identity provider.

If a user's email changes, Sequence treats them as a new user. They'll need an invite, or are added automatically if just-in-time provisioning is on. Reach out to your Sequence representative if you're planning a migration.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.