Firms on plans that include enterprise authentication can sign in through their own identity provider (IdP) and automatically provision users. Tallyfor supports any SAML 2.0 identity provider, including Okta and Microsoft Entra ID, plus SCIM 2.0 (RFC 7643/7644) for user provisioning.
Set up SAML SSO
Go to Settings → Single Sign-On (firm owner/admin only).
Click Contact support to set up SSO. Tallyfor support provisions the SAML connection for your workspace — you'll exchange your IdP's details (Entity ID, sign-on URL, X.509 certificate) with our team.
Once provisioned, test sign-in with one user before enforcing SSO for the whole firm.
Enforcement
After SSO is verified, enforcement can be enabled so team members must sign in through your IdP rather than Google/Microsoft sign-in. Leave enforcement off while testing so you don't lock anyone out.
SCIM provisioning
With SCIM enabled, your IdP manages the Tallyfor user lifecycle automatically:
Create — users assigned to the app in your IdP are provisioned in Tallyfor
Update — name/email changes sync automatically
Deactivate — users removed in your IdP lose Tallyfor access
Group → role mapping — map IdP groups to Tallyfor roles so access levels stay in sync
SCIM credentials (token and base URL) are provided during provisioning; paste them into your IdP's provisioning configuration.
Troubleshooting
Sign-in fails after setup: confirm the X.509 certificate is the current signing certificate and that the Entity ID and SSO URL match your IdP exactly.
Locked out with enforcement on: contact Tallyfor support — we can temporarily lift enforcement for your firm.