Open Settings from the Dock (the app bar at the bottom of the screen). Then
select Single Sign-On (SSO) under Workspace Settings.This page is visible to admins only.
Domains
The Domains section lists every email domain your workspace has registered for SSO authentication (for example,acme.com). Default fetches the current state of each domain
and shows it as a badge.
Add a domain
Select Add domain to open the WorkOS Admin Portal. Follow the steps in the portal to add and verify your domain. Verification usually involves a DNS TXT record. When verification completes, Default shows the domain with a Healthy badge.Remove a domain
To remove a domain, select the trash icon on its row. Default asks you to type the domain name exactly to confirm, for exampleacme.com. The
removal takes effect only after you confirm.
Single Sign-On
The Single Sign-On section lists the SSO connections your workspace has configured through the Admin Portal. Each connection shows a name, the connection type (such asOkta SAML), and its current state as a badge.
Set up or manage SSO
Select Set up SSO to open the WorkOS Admin Portal. Create your first SSO connection there. After a connection exists, the button changes to Manage SSO. Use it to edit, test, or remove connections.Set up SSO is disabled until you have at least one verified domain. Default shows
a prompt (“Verify a domain to enable SSO setup”) until that condition is met.
Example: verify a domain, then connect SSO
1
Add and verify your domain
In the Domains section, select Add domain. The Admin Portal opens.Enter your domain, for example
acme.com. Follow the DNS verification steps.When verification completes, the domain appears with a Healthy badge.2
Set up your SSO connection
In the Single Sign-On section, select Set up SSO. The Admin Portal opens to
the SSO configuration flow.Choose your identity provider, such as Okta or Microsoft Entra. Complete the setup.Activate the connection. The connection appears in Default with an Active badge.
3
Confirm your team can sign in
Ask a team member to sign in with their
acme.com email. Default routes them through
your identity provider.After this test succeeds, SSO is live for your workspace.