Skip to main content

SAML Single Sign-On (SSO) and SCIM Provisioning

Configure SAML SSO with your identity provider and automate user provisioning with SCIM.

Firms on plans that include enterprise authentication can sign in through their own identity provider (IdP) and automatically provision users. Tallyfor supports any SAML 2.0 identity provider, including Okta and Microsoft Entra ID, plus SCIM 2.0 (RFC 7643/7644) for user provisioning.

Set up SAML SSO

  1. Go to Settings → Single Sign-On (firm owner/admin only).

  2. Click Contact support to set up SSO. Tallyfor support provisions the SAML connection for your workspace — you'll exchange your IdP's details (Entity ID, sign-on URL, X.509 certificate) with our team.

  3. Once provisioned, test sign-in with one user before enforcing SSO for the whole firm.

Enforcement

After SSO is verified, enforcement can be enabled so team members must sign in through your IdP rather than Google/Microsoft sign-in. Leave enforcement off while testing so you don't lock anyone out.

SCIM provisioning

With SCIM enabled, your IdP manages the Tallyfor user lifecycle automatically:

  • Create — users assigned to the app in your IdP are provisioned in Tallyfor

  • Update — name/email changes sync automatically

  • Deactivate — users removed in your IdP lose Tallyfor access

  • Group → role mapping — map IdP groups to Tallyfor roles so access levels stay in sync

SCIM credentials (token and base URL) are provided during provisioning; paste them into your IdP's provisioning configuration.

Troubleshooting

Sign-in fails after setup: confirm the X.509 certificate is the current signing certificate and that the Entity ID and SSO URL match your IdP exactly.

Locked out with enforcement on: contact Tallyfor support — we can temporarily lift enforcement for your firm.

Did this answer your question?