Open Settings from the Dock (the app bar at the bottom of the screen), then
select Single Sign-On (SSO) under Workspace Settings. This page is visible to
admins only.
Domains
The Domains section lists every email domain your workspace has registered for SSO authentication (for example,acme.com). Default fetches the current state of each domain
and shows it as a badge.
Add a domain
Select Add domain to open the WorkOS Admin Portal. Follow the steps in the portal to add and verify your domain (usually involves adding a DNS TXT record). When verification completes, Default shows the domain with a Healthy badge.Remove a domain
To remove a domain, select the trash icon on its row. Default asks you to type the domain name exactly to confirm (for example,acme.com) before the removal takes effect.
Single Sign-On
The Single Sign-On section lists the SSO connections your workspace has configured through the Admin Portal. Each connection shows a name, the connection type (such asOkta SAML), and its current state as a badge.
Set up or manage SSO
Select Set up SSO to open the WorkOS Admin Portal and create your first SSO connection. Once a connection exists, the button changes to Manage SSO. Use it to edit, test, or remove connections.Set up SSO is disabled until you have at least one verified domain. Default shows
a prompt (“Verify a domain to enable SSO setup”) until that condition is met.
Example: verify a domain, then connect SSO
1
Add and verify your domain
In the Domains section, select Add domain. The Admin Portal opens. Enter your
domain (for example,
acme.com) and follow the DNS verification steps. When
verification completes, the domain appears with a Healthy badge.2
Set up your SSO connection
In the Single Sign-On section, select Set up SSO. The Admin Portal opens to
the SSO configuration flow. Choose your identity provider (such as Okta or Microsoft
Entra), complete the setup, and activate the connection. The connection appears in
Default with an Active badge.
3
Confirm your team can sign in
Ask a team member to sign in with their
acme.com email. Default routes them through
your identity provider. Once confirmed, SSO is live for your workspace.