Loading article…
Loading article…
Last updated on Aug 30, 2026
Enterprise Single Sign-On lets people in your organization reach Maxio through your own identity provider, so they authenticate against the account your IT team already manages instead of holding a separate Maxio password. If your people have access to more than one Maxio organization, see Switch Organizations from Maxio Core for moving between them.

Enterprise SSO changes where authentication happens and who controls it:
Maxio asks for an email address before it asks for a password. If that address belongs to a user who authenticates through your identity provider, Maxio hands the sign-in over to it rather than showing a password field. There is no separate button to select, and the reader does not need to know in advance which type of account they have.
Maxio supports three connection types, chosen when an administrator creates the connection:
| Connection type | Typical use |
|---|---|
| Okta | An organization whose identity provider is Okta. |
| Google Workspace | An organization that manages accounts in Google Workspace. |
| SAML | Any identity provider that supports SAML, where you supply a sign-in URL and a signing certificate rather than a client ID and secret. |
Your identity provider's security policies decide whether a second factor is required and what form it takes. Maxio does not apply its own 2FA to these users, and Maxio administrators cannot turn 2FA on or off for them.
Before an administrator can create a connection, three things have to be true:
Maxio creates the connection, but the identity provider side belongs to your team. After the connection is created, Maxio displays a callback URL that you set in your identity provider, plus an Entity ID for SAML connections. Sign-in does not work until that is in place. Your team also owns the client credentials or signing certificate, and rotating them when they expire.
An account can hold one Enterprise SSO connection at a time. You cannot run two connection types side by side, so an organization consolidating from one identity provider to another replaces the connection rather than adding a second.
To create the connection, see the Set Up Enterprise SSO help article.
To learn how Enterprise SSO fits into Maxio's wider sign-in experience, see the Understand Universal Login help article.
Still need help?
Reach out and our support team will take it from here.