> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cloud.cdata.com/llms.txt
> Use this file to discover all available pages before exploring further.

# SSO

> Connect AI supports Single Sign-On (SSO) with multiple identity providers.

Connect AI supports the following SSO providers. When you onboard with Connect AI, CData provides a self-service link that explains how to set up your SSO provider. Click the link to view FAQ/Troubleshooting information for each SSO provider.

* [SAML](/en/SAMLTroubleshooting)
* [OpenID Connect](/en/OpenIDConnectTroubleshooting)
* [Google Workspace](/en/GoogleWorkspaceTroubleshooting)
* [Microsoft Entra ID](/en/MicrosoftEntraIDTroubleshooting)
* [Active Directory Federation Services (ADFS)](/en/ADFSTroubleshooting)
* [Active Directory/LDAP](/en/ActiveDirectoryLDAPTroubleshooting)
* [PingFederate](/en/PingFederateTroubleshooting)
* [Okta Workforce Identity Cloud](/en/OktaTroubleshooting)

To enable SSO for your account, contact [CData Support](https://www.cdata.com/support/submit.aspx).

## SSO User Provisioning (Without JIT)

SSO handles authentication only. Before a user can sign in via SSO, they must have a Connect AI account. Without JIT provisioning enabled, an Administrator must invite the user by email first. See [Users](/en/Users) for details.

## JIT User Provisioning

JIT provisioning automatically creates a user account the first time someone successfully authenticates through SSO. The Connect AI Administrator does not have to invite the user manually. The new user receives the role that has been configured by the Administrator in the **Settings** page (the **Security** tab) by turning on **Just-in-Time User Provisioning** for the selected email domain and role.

<Frame>
  <img src="https://mintcdn.com/cdata/BVI_pWskwfkvIuSe/en/images/settings_sso.png?fit=max&auto=format&n=BVI_pWskwfkvIuSe&q=85&s=b60c22f0afbb495ad9c766a58034d345" alt="JIT Provisioning" width="1447" height="281" data-path="en/images/settings_sso.png" />
</Frame>

An Administrator or User Administrator can modify the roles and permissions later. See [Permissions and Access Control](/en/Permissions) for details on user roles and permissions.

<Note>Your account must already have SSO configured to enable JIT provisioning.</Note>

If the new user's SSO login reaches the maximum number of seats, the user's provisioning is denied. The Administrator receives an alert.
