SSO and Directory Sync are available on Enterprise plans. Workspace admins can set up and manage SSO directly from Settings > Security without contacting support.
When to Use What
Supported Protocols
Supported Identity Providers
Exec integrates with any identity provider that supports SAML 2.0 or OpenID Connect. The following providers have been tested and have guided setup documentation available:If your identity provider is not listed above, reach out to us at [email protected]. We can support any provider that implements SAML 2.0, OIDC, or SCIM 2.0 standards.
How It Works
Single Sign-On (SSO)
SSO allows your employees to access Exec using their existing corporate credentials through your organization’s identity provider. Once SSO is enabled for a workspace, it becomes the mandatory authentication method for all users in that workspace.Directory Sync (SCIM)
Directory Sync provides automated user lifecycle management by connecting Exec to your organization’s directory. When an employee is added to or removed from the appropriate group in your identity provider, their Exec account is automatically provisioned or deprovisioned.Setting Up SSO
Workspace admins can set up SSO directly from the Exec dashboard. The setup process walks you through domain verification, identity provider configuration, and optional directory sync.1
Go to Settings > Security
Navigate to Settings > Security in your Exec workspace. You’ll see the SSO setup wizard if your plan includes SSO.
2
Add and Verify Your Domains
Enter your company’s email domains (e.g.
acme.com). You’ll be guided through a DNS verification process to prove domain ownership. You can add multiple domains.3
Connect Your Identity Provider
Once at least one domain is verified, click Configure to open the WorkOS Admin Portal. Follow the step-by-step instructions for your specific identity provider (Okta, Azure AD, Google Workspace, etc.).
4
Enable Directory Sync (Optional)
After SSO is active, you can optionally enable Directory Sync (SCIM) from the same Security settings page. This automates user provisioning and deprovisioning from your identity provider.
Disabling SSO or Directory Sync
You can disable SSO or Directory Sync at any time from Settings > Security.
Your verified domains are preserved when you disable SSO, so you can re-enable it later without going through domain verification again.
Frequently Asked Questions
Can users still log in with a password after SSO is enabled?
Can users still log in with a password after SSO is enabled?
No. Once SSO is enabled for a workspace, all users must authenticate through your identity provider. Password-based login is no longer available for that workspace.
Do we need SCIM if we already have SSO?
Do we need SCIM if we already have SSO?
No, SCIM is optional. SSO alone provides centralized authentication. SCIM adds automated provisioning and deprovisioning, which is recommended for organizations that want to reduce manual user management.
Is MFA supported?
Is MFA supported?
Exec relies on your identity provider for multi-factor authentication. When SSO is enabled, your organization’s MFA policies are enforced through your identity provider during the authentication flow.
What identity providers do you support?
What identity providers do you support?
We support any provider that implements SAML 2.0 or OpenID Connect, which covers virtually all enterprise identity providers. See the full list above.
What happens when I disable SSO?
What happens when I disable SSO?
All members revert to password-based sign-in and are unlinked from the identity provider. If Directory Sync is enabled, it is also disabled. Your verified domains are preserved so you can re-enable SSO later without re-verifying them.
Can I set a default seat type for SCIM-provisioned users?
Can I set a default seat type for SCIM-provisioned users?
Yes. In Settings > Security, you can choose whether users provisioned through SCIM are assigned full seats or basic seats by default.