--- title: "SSO Settings" slug: "sso-settings" updated: 2024-09-22T21:24:12Z published: 2024-09-22T21:24:12Z canonical: "docs.processmaker.com/sso-settings" --- > ## Documentation Index > Fetch the complete documentation index at: https://docs.processmaker.com/llms.txt > Use this file to discover all available pages before exploring further. # SSO Settings > [!TIP] > [**Plan Availability:**](https://www.processmaker.com/products/pricing/) ![Professional](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/Standard.png)![Professional](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/Professional.png)![Enterprise](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/Enterprise.png) ## What is Single Sign-On (SSO)? Single Sign-On (SSO) allows a user to sign on with one set of credentials to log on to ProcessMaker. This increases security and provides a better user experience for customers, employees, and partners by reducing the number of required accounts/passwords. As a prerequisite to enable SSO, the Administrator must implement an Identity Provider. If you use a centralized user system, such as Microsoft or Google, you already have access to an Identity Provider. > [!WARNING] > ### Notice to Administrators > > [Enhance security for your ProcessMaker Platform instance by following these best practices](/v1/docs/enhance-processmaker-platform-security). Among these best practices are to require all ProcessMaker users to log on to your ProcessMaker Platform instance via Single Sign-On (SSO), OAuth, OKTA and/or two-factor authentication. To use one or more Identity Providers, view SSO settings, and then enable the toggle key for the Identity provider(s). Doing so adds a new **Settings** tab to configure that specific Identity Provider. ProcessMaker Platform supports the following Identity Providers: - [Atlassian](/v1/docs/sso-atlassian-settings) - [Auth0](/v1/docs/sso-auth0-settings) - [Facebook](/v1/docs/sso-facebook-settings) - [GitHub](/v1/docs/sso-github-settings) - [Google](/v1/docs/sso-google-settings) - [Keycloak](/v1/docs/sso-keycloak-settings) - [Microsoft](/v1/docs/sso-microsoft-settings) - [SAML](/v1/docs/sso-saml-settings) ## View SSO Settings Display all [SSO](/v1/docs/sso-settings#what-is-single-sign-on-sso) settings in one location. This makes it easy to manage these settings. **Permissions** Your user account or group membership must have the "Settings: Update Settings" permission to view SSO settings unless your user account has the **Make this user a Super Admin** setting selected. See the Settings permissions or ask your Administrator for assistance. Follow these steps to view all SSO settings to synchronize users in your organization: 1. Ensure that you are [logged on](/v1/docs/participant-basics#log-on-to-processmaker-platform) to ProcessMaker. 2. Click the **Admin** option from the top menu. The **Users** page displays. 3. Click the **Settings** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/db13dd4c-a949-443a-8606-f7bf2c326f0d.png) from the left sidebar to view all settings. 4. From the **Settings** panel on the left, expand the **Log-in & Auth** section. 5. Select **SSO** to view the following details: - **Setting:** The **Setting** column displays the SSO Setting name. - **Configuration:** The **Configuration** column displays the setting value and how it is configured. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/629efd92-8807-419c-9995-9a8bf95f261d.png) Settings to enable logon through SSO > ### Search for an SSO Setting > > Follow the next steps to search for a setting: > > 1. In the **Search** setting, enter the **Setting** name to filter settings. > 2. Click the **Search** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/bc897ac0-9423-4922-93e2-bc34b0ba145c.png) or press enter to view SSO settings that match your entered text. ## Configure SSO Settings > [!WARNING] > ### Notice to Administrators > > [Enhance security for your ProcessMaker Platform instance by following these best practices](/v1/docs/enhance-processmaker-platform-security). Among these best practices are to require all ProcessMaker users to log on to your ProcessMaker Platform instance via Single Sign-On (SSO), OAuth, OKTA and/or two-factor authentication. **Permissions** Your user account or group membership must have the "Settings: Update Settings" permission to edit SSO settings unless your user account has the **Make this user a Super Admin** setting selected. See the Settings permissions or ask your Administrator for assistance. Configure the following [SSO](/v1/docs/sso-settings#what-is-single-sign-on-sso) settings as necessary: - [Enable standard login](/v1/docs/sso-settings#enable-standard-login) - [Enable automatic registration](/v1/docs/sso-settings#enable-automatic-registration) - [Enable permissions for SSO users](/v1/docs/sso-settings#enable-permissions-for-sso-users) - [Enable groups for SSO users](/v1/docs/sso-settings#enable-groups-for-sso-users) - [Copy permissions and groups for SSO Users](/v1/docs/sso-settings#copy-permissions-and-groups-for-sso-users) - [Enable debug mode](/v1/docs/sso-settings#enable-debug-mode) - [Enable SSO identity providers](/v1/docs/sso-settings#enable-sso-identity-providers) ### Enable Standard Login Enable to display settings to log on using user credentials. When disabled, settings only display SSO log on options. Follow these steps to enable display settings for standard log on: 1. [​View your SSO settings](/v1/docs/sso-settings#view-sso-settings). The **SSO** tab displays. 2. Enable the **Allow Standard Login** toggle key. The following message displays: **The setting was updated.** 3. [Review, and then configure other SSO settings as necessary](/v1/docs/sso-settings#configure-sso-saml-settings). ### Enable Automatic Registration Enable whether SSO users should automatically register the first time that they log on. Follow these steps to enable automatic registration: 1. [​View your SSO settings](/v1/docs/sso-settings#view-sso-settings). The **SSO** tab displays. 2. Enable the **Automatic Registration** toggle key. The following message displays: **The setting was updated.** 3. [Review, and then configure other SSO settings as necessary](/v1/docs/sso-settings#configure-sso-saml-settings). ### Enable Permissions for SSO Users Specify which permissions to assign new users that are created via SSO: Follow these steps to specify which user permissions to assign new users created via SSO: 1. [View your SSO settings](/v1/docs/sso-settings#view-sso-settings). The **SSO** tab displays. 2. Click the **Edit** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/1723ec45-8b4a-49de-8617-9870f0ca7e30.png) for the **New User Default Config** setting. The **New User Default Config** screen with the **Permissions** tab displays. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/96a6f5cf-5cd6-4a2f-a4c6-0312d9074e43.png) 3. Select a collapsed permission category to expand the view of individual permissions within that category. Otherwise, select an expanded permission category to collapse that category. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/79de954b-2888-4a31-b848-b40762f2fa56.png) 4. Enable permissions as necessary. See [Permission Descriptions for Users and Groups](/v1/docs/permission-descriptions-for-users-and-groups) for descriptions. 5. Click **Save**. The following message displays: **The setting was updated.** 6. [Review, and then configure other SSO settings as necessary](/v1/docs/sso-settings#configure-sso-saml-settings). ### Enable Groups for SSO Users Select to which groups to assign users created via SSO. Follow these steps to select to which groups to assign users created via SSO: 1. [​View your SSO settings](/v1/docs/sso-settings#view-sso-settings). The **SSO** tab displays. 2. Click the **Edit** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/1723ec45-8b4a-49de-8617-9870f0ca7e30.png) for the **New User Default Config** setting. The **New User Default Config** screen with the **Permissions** tab displays. 3. Click the **Groups** tab. All available groups display. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/6037e0e8-3df9-45a9-a238-49d567b41363.png) 4. Enable groups as necessary. 5. Click **Save**. The following message displays: **The setting was updated.** 6. [Review, and then configure other SSO settings as necessary](/v1/docs/sso-settings#configure-sso-saml-settings). ### Copy Permissions and Groups for SSO Users Copy to clipboard a JSON-formatted object of all assigned permissions and groups for users created via SSO. Follow these steps to copy the permissions and groups for SSO users: 1. [​View your SSO settings](/v1/docs/sso-settings#view-sso-settings). The **SSO** tab displays. 2. Click the **Copy to Clipboard** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/0bc32ae6-9a4b-47ee-a6d9-b051526ce9a8.png) for the **New User Default Config** setting. The following message displays: **The setting was copied to your clipboard**. 3. [Review, and then configure other SSO settings as necessary](/v1/docs/sso-settings#configure-sso-saml-settings). ### Enable Default SSO Login Select a default SSO integration to allow users be automatically redirected to the IDP Single Sign On log on page instead of displaying the normal Login page. When the user goes to the log on page, that user is redirected to the selected provider. Follow these steps to enable default SSO Integration: 1. [​View your SSO settings](/v1/docs/sso-settings#view-sso-settings). The **SSO** tab displays. 2. Click the **Edit** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/1723ec45-8b4a-49de-8617-9870f0ca7e30.png) for the **Default SSO Login** setting. The **Default SSO Login** screen with the SSO identity providers displays. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/cb5b9db7-0371-4117-8146-2fdeac4bb164.png) 3. Select an SSO identity provider among: - [Atlassian](/v1/docs/sso-atlassian-settings) - [Auth0](/v1/docs/sso-auth0-settings) - [Facebook](/v1/docs/sso-facebook-settings) - [GitHub](/v1/docs/sso-github-settings) - [Google](/v1/docs/sso-google-settings) - [Keycloak](/v1/docs/sso-keycloak-settings) - [Microsoft](/v1/docs/sso-microsoft-settings) - [SAML](/v1/docs/sso-saml-settings) - Select the **ProcessMaker** SSO login option if you do not want an SSO identity provider as the default log on. This option ensures LDAP users to verify accounts in ProcessMaker Platform. This option also helps to log on as an administrator while fixing SSO problems. 4. Click **Save**. The following message displays: **The setting was updated.** 5. [Review, and then configure other SSO settings as necessary](/v1/docs/sso-settings#configure-sso-saml-settings). ### Enable Debug Mode Select whether detailed SSO errors should be displayed. It is recommended to disable the debug mode in production servers. Follow these steps to enable automatic registration: 1. [View your SSO settings](/v1/docs/sso-settings#view-sso-settings). The **SSO** tab displays. 2. Switch on the **Debug Mode** toggle key. The following message displays: **The setting was updated.** 3. [Review, and then configure other SSO settings as necessary](/v1/docs/sso-settings#configure-sso-saml-settings). ### Enable SSO Identity Providers Select whether to enable single sign-on via SSO identity providers to log on as necessary. The SSO identity provider options display on the log on screen. 1. [​View your SSO settings](/v1/docs/sso-settings#view-sso-settings). The **SSO** tab displays. 2. Enable any of the following SSO identity providers as necessary: - [Atlassian](/v1/docs/sso-atlassian-settings) - [Auth0](/v1/docs/sso-auth0-settings) - [Facebook](/v1/docs/sso-facebook-settings) - [GitHub](/v1/docs/sso-github-settings) - [Google](/v1/docs/sso-google-settings) - [Keycloak](/v1/docs/sso-keycloak-settings) - [Microsoft](/v1/docs/sso-microsoft-settings) - [SAML](/v1/docs/sso-saml-settings) The following message displays: **The setting was updated.** 3. [Review, and then configure other SSO settings as necessary](/v1/docs/sso-settings#configure-sso-saml-settings). ## Related - [SSO - Atlassian Settings](/sso-atlassian-settings.md) - [SSO - Auth0 Settings](/sso-auth0-settings.md) - [SSO - Facebook Settings](/sso-facebook-settings.md) - [SSO - GitHub Settings](/sso-github-settings.md) - [SSO - Google Settings](/sso-google-settings.md) - [SSO - Keycloak Settings](/sso-keycloak-settings.md) - [SSO - Microsoft Settings](/sso-microsoft-settings.md) - [SSO - SAML Settings](/sso-saml-settings.md)