SAML
SAML (Security Assertion Markup Language) is a standard that allows your organization to manage sign-in centrally, using an external identity provider (IdP) such as Microsoft Entra ID, Okta, Azure AD, or Google Workspace.
What it is used for
In Gredit, the SAML integration serves two distinct purposes that are configured separately:
- Single Sign-On (SSO): Allows users to log into Gredit with their corporate account, without needing a tool-specific password.
- User import: Allows users to be brought in from groups defined in the corporate directory (e.g., Azure), avoiding manual creation one by one. Users are created and kept in sync with those groups.
Configuration flexibility
You are not required to configure both features. You can choose based on your organization's policy:
| Configuration | What you need |
|---|---|
| Import only | Application registration in Entra ID with Microsoft Graph permissions (Tenant ID, Client ID, Client secret) and the SAML import screen in Gredit |
| SSO login only | Enterprise application with SAML metadata and certificates, and the Gredit SSO SAML form |
| Import and SSO | Both configurations above. In Microsoft, one or two applications can be used depending on how the tenant is set up |
The same identity ecosystem (SAML / Microsoft Entra ID) can be used for SSO login, for importing and maintaining users by groups, or for both.
Sections
Relationship with other modules
- Authenticates Users with a SAML origin
- Alternative to LDAP for SSO
- Recorded in Login records
- Roles are assigned based on the roles attribute mapping