# Single sign-on


> Connect your own identity provider over SAML so people sign in with your organization's account and your policies apply.
SAML single sign-on puts Screenly behind your own identity provider. People sign in with the account they already have, and your rules on multi-factor, device posture, and session length apply without Screenly needing to know about any of them.

Deprovisioning is the practical reason to bother. When someone leaves and you disable their account centrally, they lose Screenly along with everything else, rather than depending on somebody remembering to remove them from a workspace.

SAML is an Enterprise feature. It is configured in your **workspace settings**, on the **Security** tab.

## Providers

Any SAML 2.0 provider works. We have setup guides for Auth0, Okta, Microsoft Entra ID, and Google Workspace.

## Without SAML

Everyone else signs in with a one-time email code, a passkey, or a Google, GitHub, or Microsoft account. Those are on every plan and need no setup. See [Signing in](/docs/account/signing-in/ways-to-sign-in/).