Single sign-on is an Enterprise feature. Settings → Single sign-on appears for admins of enterprise workspaces.
Set up
1
Add your domain
Enter your company domain, such as
acme.com, and click Add domain.2
Prove you own it
Henry shows a DNS record: a host name and a value. Add it at your DNS provider, then click Verify domain. The status reads Awaiting DNS verification until the record is found.
3
Connect your identity provider
Create a SAML application in Okta, Entra ID, or your IdP. Paste its metadata URL or XML into Henry and click Connect IdP. The status becomes Active, optional: people at your domain can use SSO, and other sign-in methods still work.
4
Test a sign-in
Sign in through SSO with a test account before enforcing it.
5
Require SSO
Click Require SSO. The status becomes Active, SSO required. From now on, email and Google sign-in are blocked for that domain.