Access control

Do you support single sign-on (SSO) for customers?

How to answer this security questionnaire question, with an expert response your security or GRC team can adapt.

Expert answer

Offer SSO via SAML 2.0 or OIDC so customers can manage authentication through their own identity provider and enforce their MFA and conditional-access policies. Support automated deprovisioning through the same integration.

What the security reviewer is checking

Enterprise buyers treat SSO as a hard procurement gate, so the reviewer is confirming three things: that SSO exists, which protocols it uses, and whether it works with their specific identity provider. Strong answers name the standards (SAML 2.0, OIDC), list verified IdPs such as Okta, Microsoft Entra ID, and Google Workspace, and state whether SSO can be enforced so users cannot bypass it with passwords. Reviewers also probe the pricing dimension — whether SSO is gated behind a top-priced tier — and whether user provisioning and deprovisioning can be automated via SCIM rather than managed manually.

Example response you can adapt

This is an illustrative template, not a real vendor's security posture. Replace every claim with what is actually true for your organization before submitting it.
Yes. We support single sign-on for customers via both SAML 2.0 and OpenID Connect, and we have verified integrations with Okta, Microsoft Entra ID, Google Workspace, and other standards-compliant identity providers. Administrators configure SSO self-service from the organization settings page using their IdP metadata, and setup guides are available for each major provider. SSO can be set to required mode, which disables password-based login for all members of the organization and routes every authentication through the customer’s IdP, so access is revoked the moment an employee is deprovisioned upstream. Just-in-time provisioning creates accounts on first SSO login with a default role, and SCIM-based provisioning and deprovisioning is supported for customers who want full lifecycle automation from their directory.

Evidence reviewers expect you to attach

  • SSO configuration documentation or admin guide for your supported IdPs
  • List of supported protocols and identity providers with any certification (e.g., Okta Integration Network listing)
  • Screenshot or documentation of the SSO enforcement (require SSO) setting
  • SCIM provisioning documentation, if supported

Follow-up questions reviewers ask next

  • Is SSO available on our contract tier, or does it require an upgrade?
  • Can password login be fully disabled once SSO is enabled?
  • Do you support SCIM for automated provisioning and deprovisioning?
  • How are roles and permissions mapped from IdP groups?
  • What happens to active sessions when a user is deprovisioned in our IdP?

Answer every security questionnaire in minutes

Wolfia drafts accurate, cited answers to security questionnaires and RFPs from your existing documentation. See it work on your own questions.Book a demo