---
locale: "en"
updated_at: "2025-10-28T12:42:04.690Z"
canonical: "https://www.isdecisions.com/en/userlock/docs/reference/server-settings/single-sign-on"
---

# Single Sign-On settings

Configure the SaaS applications.

> **Note**
>
> - To access this page, go to **Server settings ▸ Single Sign-on**.
> - You need at least *read* [permission](/userlock/docs/reference/server-settings/permissions) on Server settings to view this page.
> - You also need a **domain administrator account** or an account that is a member of the **Active Directory group "UserLock SSO Admins". **If the group does not exist, you must create it.

## Overview

UserLock Single Sign-On (SSO) lets users authenticate once with their Windows credentials and then access SaaS applications without re-entering their passwords.

To activate SSO for an application, complete its connection details and restart the SSO service.

The SSO settings page displays:

- The **main SSO service** and its current status
- Any **backup servers**, if configured. 
→ See [how to install a backup SSO server](/userlock/docs/guides/sso/install-backup-sso-server) guide.
- The **certificate validity period.** 
→ See [how to renew the SAML certificate](/userlock/docs/guides/sso/renew-saml-certificate) guide.
- A list of supported SaaS applications, grouped under **Configured** and **Not configured**.

## Configure your SaaS application

1. Choose the SaaS application you want to connect (for example, Microsoft 365, Salesforce, or Slack).
2. Complete the required fields according to the selected provider.

![](https://a.storyblok.com/f/122374/1763x997/24b495435b/server-settings-single-sign-on.png)

> **Note**
>
> Depending on the provider, you can create **multiple SSO profiles**.

#### Provider-specific configuration:

| **Provider** | **Details** |
| --- | --- |
| **Adobe Sign** | [Secure Adobe Sign access with UserLock Single Sign-On](/userlock/docs/guides/sso/configure-the-applications/adobesign) |
| **AWS** | [Configure AWS for UserLock SSO](/userlock/docs/guides/sso/configure-the-applications/aws) |
| **Box** | [Enable Single Sign-On to Box with UserLock](/userlock/docs/guides/sso/configure-the-applications/box) |
|  |
| **DocuSign** | [Integrate DocuSign with UserLock Single Sign-On](/userlock/docs/guides/sso/configure-the-applications/docusign) |
| **DropBox** | [Enable Single Sign-On to Dropbox with UserLock](/userlock/docs/guides/sso/configure-the-applications/dropbox) |
| **Google Workspace** | [Configure Google Workspace for UserLock SSO](/userlock/docs/guides/sso/configure-the-applications/google-workspace) |
| **Microsoft** | [Secure Microsoft access with UserLock Single Sign-On](/userlock/docs/guides/sso/configure-the-applications/microsoft/configure) |
| **Salesforce** | [Configure Salesforce for UserLock Single Sign-On](/userlock/docs/guides/sso/configure-the-applications/salesforce) |
| **ServiceNow ** | [Configure ServiceNow for UserLock Single Sign-On](/userlock/docs/guides/sso/configure-the-applications/servicenow) |
| **Slack** | [Configure Slack for UserLock Single Sign-On](/userlock/docs/guides/sso/configure-the-applications/slack) |
| **Slite** | [Configure Slite for UserLock Single Sign-On](/userlock/docs/guides/sso/configure-the-applications/slite) |
| **Zendesk** | [Configure Zendesk for UserLock Single Sign-On](/userlock/docs/guides/sso/configure-the-applications/zendesk) |
| **Other** | [Configure a Non-Supported SaaS Application](/userlock/docs/guides/sso/configure-the-applications/configure-non-supported-saas-application) |

## Download metadata and certificates 

In the **top right corner**, you can:

- Download the SSO **metadata**
- Download the **SAML certificate**

These files may be required by the SaaS application during setup.
