About Single Sign-On
Single Sign-On (SSO) in Iru Endpoint allows team members to log into the Iru Endpoint Web App using their existing identity provider credentials, providing centralized authentication management.How It Works
Team Members have four options for logging into the Iru Endpoint Web App: Passkeys, Google Social, Microsoft Social and Single Sign-On (SSO). By default, Passkeys, Google Social, and Microsoft Social authentication are activated for all tenants, offering login through Passkeys, Google, Microsoft. Admins have the option to enable SSO using either native integrations or Custom SAML. Once an SSO setup is complete, the default connections can be turned off, allowing SSO to be the only login method. SSO can also be used for Require Authentication in the Automated Device Enrollment Library Item. To learn more about requiring authentication during enrollment, see this support article.SSO Connection Types
Iru Endpoint currently supports the following Single Sign-on connection types. Click on one of the following connection types to learn how it can be configured.- Single Sign-on with Microsoft Entra ID (Native)
- Single Sign-On with Microsoft Entra ID (SAML)
- Single Sign-On with Google Workspace (Native)
- Single Sign-On with Google Workspace (SAML)
- Single Sign-On with Okta (SAML)
- Single Sign-On with JumpCloud (SAML)
- Single Sign-On with OneLogin (SAML)
- Custom SAML-based Single Sign-On
Allowing Tenant Authentication and Managing Connections
Once you have configured an SSO connection in both Iru Endpoint and your identity provider (IdP), you can allow the SSO connection to be used for tenant authentication.1
Access Connection Menu
Click the ellipsis next to the connection name.
2
Allow for Tenant Authentication
Click Allow for tenant authentication from the menu. Connections can also be re-configured, deleted, and disabled from this menu.
Considerations
- An SSO connection does not need to be allowed for tenant authentication to be used for Require Authentication during Device Enrollment.
- A connection should only set to Allow tenant authentication in Settings if you want to authenticate Iru Endpoint administrators to the web app with that connection.
- Authentication to the Iru Endpoint Web App using SSO requires that the user has been invited as a Team Member.
Enforcing Single Sign-On
Once you have configured at least one Single Sign-on connection, and logged in with that connection, you can disable the Passkey, Google Social, and Microsoft Social connections. Disabling these connections will disable the ability for Iru Endpoint administrators in your tenant to authenticate via Google or Microsoft social logins, and Passkeys.1
Navigate to the Account Menu Button
In Iru Endpoint, in the sidebar, click the Account Menu Button.
2
Access Authentication Settings
Click the Access option in the menu.
3
Connection Menu
Click the ellipsis next to Passkey.
4
Disable for Passkey Tenant Authentication
Click Disable for tenant authentication
5
Disable Social Tenant Authentication
Repeat the previous steps for the Google Social and Microsoft Social connections.
If you lose access to your Iru Endpoint tenant via SSO and need to have Passkey, Google Social, or Microsoft Social connections re-enabled, please contact Iru Endpoint support.