Enterprise
Single sign-on for teams that answer to IT
Orion connects to standard enterprise identity providers — Okta, Microsoft Entra ID (Azure AD) and Google Workspace — over SAML 2.0 or OIDC. Your people sign in with the credentials they already have, and your identity team keeps control of who gets in.
Supported identity providers
Okta
SAML 2.0 or OIDC
Create a SAML app integration, paste Orion's ACS URL and Entity ID, then share the IdP metadata URL.
Microsoft Entra ID (Azure AD)
SAML 2.0 or OIDC
Add a non-gallery enterprise application, set the Reply URL and Identifier, then copy the App Federation Metadata URL.
Google Workspace
SAML 2.0 or OIDC
Add a custom SAML app, upload Orion's SP details and share the IdP metadata. Google sign-in already works out of the box for non-SAML teams.
Any other SAML 2.0 compliant IdP (OneLogin, JumpCloud, Ping Identity, Keycloak) works the same way — if it publishes metadata, Orion can connect to it.
What makes it enterprise compliant
Central control
Access is granted and revoked in the customer's IdP. Offboarding a staff member in Okta or Entra ID removes their Orion access immediately.
Domain-verified identity
Connections are bound to verified email domains, so no one can claim a company's users by signing up with a lookalike address.
MFA and policy inheritance
Orion inherits the IdP's MFA, conditional access and password policies — no separate credentials to manage or audit.
Role separation
Roles are stored server-side and checked on every request, so an SSO user only sees the workspace and data their role permits.
Onboarding checklist
- 1Confirm the email domains the customer owns (e.g. acme.com, acme.co.za) — SSO is scoped to verified domains only.
- 2Send the customer Orion's service provider details: ACS (reply) URL and Entity ID.
- 3Receive the IdP metadata URL (or metadata XML) from their identity team.
- 4Map required attributes: NameID = email, plus first name, last name.
- 5Register the connection, then test with one pilot user before rolling out.
- 6Optional: enforce SSO-only sign-in for those domains so password logins are disabled.
Typical turnaround is one working day once the IdP metadata and verified domains are supplied. Email support@orionmarketing.app to start.