Single sign-on (SSO)

Configure authentication for access to the Zefi Dashboard with an Identity Provider.

Single Sign-On (SSO) allows your team to sign in through an Identity Provider (IdP) using one set of credentials and access multiple applications, such as Zefi. Enabling SSO for your team increases security and makes it easier for them to sign in to Zefi. Zefi specifically supports Security Assertion Markup Language (SAML) 2.0, so your IdP can manage the creation of user accounts (team members) as well as authentication and authorization during sign-in. Any identity provider that supports SAML 2.0 works with Zefi.

Security Incidents:
If your Identity Provider (IdP) is compromised, unauthorized parties could access your Zefi account. You’re responsible for mitigating your exposure to security incidents by evaluating your security needs and implementing the necessary security protocols and controls.

Supported features

Zefi supports the following SSO features:
Check circle icon blue
SSO configuration options:
Configure Zefi accounts to either mandate SSO for all users or allow sign-in using SSO or email and password.
Check circle icon blue
Just-In-Time account creation:
Automatically create new Zefi accounts for users without existing access upon their first SSO sign-in.
Check circle icon blue
Granular Dashboard roles:
Assign granular user roles through your IdP.
Check circle icon blue
IdP-initiated SSO:
Authenticate directly from an IdP’s website or browser extension.
Check circle icon blue
Service Provider-initiated SSO:
Initiate SSO login directly from Zefi’s login page.
Check circle icon blue
System for Cross-domain Identity Management (SCIM):
SCIM is a protocol that an IdP can use to synchronize user identity lifecycle processes (for example, provisioning and deprovisioning access, and populating user details) with the service provider, such as Zefi.

Limitations

Zefi doesn’t support the following SSO features:
Icon x rounded red
User Deletion in SAML:
When users aren’t managed through SCIM, Zefi doesn’t receive immediate notifications if user access is revoked in IdP. If users attempt to log in through SSO after their session expires, Zefi revokes their access. To remove access immediately, you can delete users from your team settings or enable SCIM user provisioning.