Sign in with the identity you already have.
Connect Google, Microsoft, Okta or a custom identity provider and staff reach PRISM without a separate password.

SAML or OIDC, your provider.
Connect over SAML 2.0 or OpenID Connect to Google Workspace, Microsoft Entra ID, Okta or any custom OIDC provider. The login screen shows a "Sign in with" button only for the providers your tenant has turned on.
One sign-on
SAML 2.0 and OIDC — Google, Microsoft, Okta or a custom IdP
Configured once for the whole tenant.
An admin sets up the identity provider once and it applies across the organisation. Restrict who the provider may sign in by listing your company email domains, and anyone with two-factor enrolled still gets challenged.
Enforced per tenant
require SSO for your whole organisation
Accounts on first sign-in.
Turn on just-in-time provisioning and a person's account is created the first time they sign in through your provider — no manual account first. Leave it off and only people who already exist can sign in.
Provisioning
just-in-time user provisioning
Single Sign-On works with what you already run.
Common questions
Which identity providers can we use?
Google Workspace, Microsoft Entra ID (Azure AD) and Okta over OAuth/OpenID Connect, a custom OpenID Connect provider, or SAML 2.0. For SAML you give your provider our sign-on (ACS) URL and metadata, then paste back its sign-in URL, issuer and signing certificate.
Do we have to create accounts before people can sign in?
Only if you want to. With just-in-time provisioning on, a matching account is created the first time someone signs in through your provider. With it off, the person must already exist in PRISM.
Is single sign-on in every plan?
No — configuring an identity provider is an Enterprise feature. If a tenant later downgrades, staff who signed in through SSO can still sign in; only setting up a new provider is gated.
One login for your whole team.
Connect your identity provider and let people into PRISM with the account they already use.



