Single sign-on
Connect your identity provider so the team can use company credentials. SAML single sign-on is available on Enterprise accounts and can be configured by an organization or agency owner or admin.
Set up the connection
Section titled “Set up the connection”- Create a SAML app in your identity provider.
- Copy the SP Entity ID and ACS URL from Infinite Audience into that app.
- Copy the provider’s entity ID, SSO URL, and signing certificate back into Infinite Audience.
- Verify your email domain with the provided DNS TXT record.
- Run a test sign-in, then activate the connection.
- Optionally enforce SSO after an administrator has completed a successful SAML sign-in.
Once active, a user who enters an email on your verified domain is sent to the company identity provider. New users can be added just in time or limited to invitations, depending on your provisioning setting.
Match the labels
Section titled “Match the labels”| Infinite Audience | Okta | Microsoft Entra ID | Google Workspace |
|---|---|---|---|
| SP Entity ID | Audience URI | Identifier (Entity ID) | Entity ID |
| ACS URL | Single sign-on URL | Reply URL | ACS URL |
| IdP Entity ID | Identity Provider Issuer | Microsoft Entra Identifier | Entity ID |
| IdP SSO URL | Identity Provider Single Sign-On URL | Login URL | SSO URL |
| Signing certificate | X.509 Certificate | Certificate (Base64) | Certificate |
Map NameID to the user’s work email in every provider.
Choose your provider
Section titled “Choose your provider”OktaCreate and connect a SAML 2.0 app.
Microsoft Entra IDConnect a non-gallery enterprise application.
Google WorkspaceConnect a custom SAML app.
DNS verificationVerify the sign-in domain with one TXT record.
TroubleshootingFind the quickest fix for common sign-in issues.
