Different IDPs may have different names for the same field. For example, Microsoft Entra uses the term Thumbprint, while Envoy uses the term Fingerprint. These values refer to the same value.
Enabling SAML for Envoy
Go to Directory Settings
Locate SAML and click Install.
Enter the fingerprint from your IdP in the Fingerprint field.
(Optional) Set SAML to required
If you'd like to configure SAML as required, we recommend first setting up SAML as optional and testing with a small group of users. Once you're sure SAML is working properly for your users, switch it to required.
Go to Apps > Directory and SSO.
Locate SAML and click Configure.
Toggle “Required” to the “on” position.
Global admins will always be able to authenticate with a password regardless of if requiring SAML is on or off.
Configuring SAML for common IdPs
You can connect Envoy to any SSO provider with SAML 2.0. We’ve provided guides for a few common IdPs: