Single Sign-On (SSO)
Enterprise identity with SAML 2.0, OIDC & SCIM provisioning
One identity across every cloud you run
Federate authentication to your existing identity provider. SAML 2.0, OpenID Connect, and SCIM user provisioning — with automatic deprovisioning the moment an employee offboards.
Overview
Enterprise Single Sign-On on VxCloud consolidates authentication across every resource your team manages — cloud accounts, Kubernetes clusters, CI/CD pipelines, databases, and internal tools — behind a single corporate identity. Integrate with Okta, Azure Active Directory, Google Workspace, OneLogin, Ping Identity, JumpCloud, Duo, and any SAML 2.0 or OpenID Connect compliant identity provider.
SCIM 2.0 provisioning automatically creates VxCloud accounts when users are added to an IdP group, updates role mappings when attributes change, and fully deprovisions access when employees leave your organization. Pair SSO with just-in-time provisioning, mandatory MFA, device-trust policies, and session management controls to meet the strictest enterprise security baselines.
What's included
Production-grade capabilities, ready to enable in your workspace.
SAML 2.0 & OIDC
Full spec compliance with signed assertions, encrypted payloads, attribute mapping, and IdP-initiated or SP-initiated flows.
SCIM 2.0 provisioning
Automated user and group lifecycle — create, update, deactivate — directly from your IdP with zero manual account management.
Group-to-role mapping
Map IdP groups to VxCloud roles and project memberships. Permission changes at the IdP propagate to the platform in seconds.
MFA enforcement
Require TOTP, WebAuthn, or IdP-delivered MFA on every login. Step-up auth for sensitive actions like production deploys.
Just-in-time provisioning
Users are provisioned the first time they authenticate. No pre-registration, no manual invites, no orphaned accounts.
Session controls
Configurable session TTL, idle timeout, forced re-authentication, and instant global logout for incident response.
Business outcomes
Measurable impact teams see when they adopt single sign-on (sso).
Reduction in password-reset tickets
Users authenticate with their corporate identity. Helpdesk stops fielding credential resets for the platform.
Automated offboarding coverage
SCIM deprovisioning removes VxCloud access the instant an employee is disabled in your IdP — no gaps.
Revocation-to-action time
Emergency logout pushes a signal to every active session. Compromised accounts lose access platform-wide.
Audit-ready access reviews
Full authentication and authorization audit trail exportable to your SIEM for quarterly access reviews.
How customers use it
Real scenarios from VxCloud customers across regulated industries and fast-moving teams.
Regulated fintech running production workloads across AWS and GCP
Centralized identity with Okta plus mandatory WebAuthn MFA satisfies PCI DSS requirement 8.3 for strong authentication.
Hospital network with rotating clinical engineering staff
Azure AD SCIM sync revokes access automatically on contract end-date — meets HIPAA access management safeguards.
Growth-stage B2B SaaS with 300 engineers and rapid hiring
Google Workspace SSO + group mapping onboards new engineers to the right projects on their first login, zero IT tickets.
State agency using PIV/CAC smartcards
SAML federation with smartcard-backed IdP satisfies NIST 800-63 AAL3 assurance level for high-impact systems.
Frequently asked questions
Still have questions? Our enterprise team answers within one business day.
Any SAML 2.0 or OIDC-compliant IdP including Okta, Azure Active Directory / Microsoft Entra ID, Google Workspace, OneLogin, Ping Identity, JumpCloud, Duo SSO, Auth0, ForgeRock, and custom internal IdPs. SCIM 2.0 provisioning is supported for Okta, Azure AD, Google Workspace, and OneLogin out of the box.
Related enterprise capabilities
Ready to move forward with Single Sign-On (SSO)?
Talk to our enterprise team — we'll scope your requirements, map the right capabilities, and build a rollout plan tailored to your organization.