Single sign-on (SSO)
To get started with SSO, reach out to your Kognic contact.
Overview
Kognic supports single sign-on, allowing your organization's users to log in through your existing identity provider instead of managing separate Kognic passwords. We support both SAML 2.0 and OpenID Connect, and SSO works with providers like Okta, Azure AD, Google Workspace, and OneLogin. SSO is configured per email domain. All users with a given domain, for example @acme.com, are routed to the same identity provider. SSO users are passwordless within Kognic, meaning there is no Kognic password to set or manage, and actions like changing your password, resetting your password, or resetting MFA are automatically hidden in the platform. All credential and MFA management is handled through your identity provider. The userβs display name in Kognic is inferred from their email address unless provided by the identity provider.
Setting up users
There are two ways users get access to the Kognic platform when SSO is enabled:
- Organization adminscan invite users from User Managementο»Ώ. The invited user receives an email with a link that routes them to the correct SSO provider. They authenticate with their identity provider and their account is activated on first login. There is no password setup step.
- Alternatively, Just-In-Time provisioning (JIT) can be enabled to link an email domain to a Kognic organization. When enabled, a user who logs in via SSO for the first time will automatically have an account created in Kognic with the Member role assigned to them. There's no need for sending out invites manually. You have full control over which users can access Kognic by managing the allowed email addresses in your identity provider.
Offboarding
When a user leaves your organization, we recommend that an administrator removes or locks the user in the Kognic platform as part of your offboarding process, in addition to deprovisioning them from your identity provider. While their Kognic user account is active, users can still use any API credentials, even though they will not be able to log in through their external SSO provider.
ο»Ώ
ο»Ώ
ο»Ώ