Company SSO

Company SSO
Company single sign-on (SSO) lets you enter DOE through your organization's login service, such as Okta, Microsoft Entra, Auth0 or Google Workspace. Your company confirms who you are; DOE workspace membership and role decide what you can open.

Sign in with company SSO
Before you start, you need:
- your work email,
- access to your company login and its security checks, and
- DOE workspace access for the same email.
Then:
- Open the DOE sign-in page.
- Choose Sign in with SSO.
- Enter your work email when DOE asks for it.
- Complete your company's login and security checks.
- Return to DOE.
DOE uses the email domain to find the correct company connection. Company SSO is different from the standard Sign in with Google button. Use the option your organization gave you.
If you cannot sign in
| What happens | What to do |
|---|---|
| The company login page blocks you | Contact the team that manages your company login |
| DOE cannot find a company connection | Check the work email, then ask your company sign-in admin or Njord delivery contact to check setup |
| The connection is disabled or unavailable | Try once more, then contact your company sign-in admin and Njord delivery contact |
| DOE asks for an invitation | Ask your DOE workspace admin to check the exact work email and access method |
| Company login succeeds but DOE blocks access | Ask your DOE workspace admin to check membership and role |
| DOE says the account already exists or cannot be matched | Use the sign-in method first connected to the account and ask an admin for help; do not create a second account |
| Your company account was removed or disabled | Ask your company sign-in admin to restore or confirm the assignment, then ask the DOE workspace admin to check access |
A DOE password reset does not change a company SSO password, bypass company MFA, or reactivate a company-managed account.
Who manages each part?
| Area | Main responsibility |
|---|---|
| Enterprise SSO connection | Your company sign-in team and Njord set up and test their respective sides together |
| Company account, password, MFA and sign-in rules | Your company sign-in team |
| DOE invitation, workspace membership and role | Your DOE workspace admin |
| Personal DOE profile details | The signed-in person, within the fields DOE allows them to edit |
| Built-in Sign in with Google connection | Njord maintains the DOE connection; Google or your Google admin manages the Google account and security checks |
| DOE email and password sign-in | Njord maintains the service; DOE requires an emailed security code by default |
Njord cannot reset a company or Google password or bypass security rules set by those services. Your company sign-in team does not choose DOE workspace roles unless the DOE workspace admin also makes that change.
Built-in Google sign-in versus Google Workspace SSO
The standard Sign in with Google button uses a Google connection maintained by Njord for DOE. Google controls the person's Google password, MFA and account status. The DOE workspace admin controls access for that Google email.
A company-owned Google Workspace SSO connection is a separate enterprise setup. Tell users which button to choose. For the built-in option, use the Google sign-in guide.
Admin-managed access
This section is for DOE workspace admins and the team that manages your company login.
Choose the access setup
| Your need | Supported approach |
|---|---|
| Let people sign in with a company account | Company SSO with Okta, Microsoft Entra, Auth0 or Google Workspace |
| Automatically add, activate or deactivate accounts | User provisioning with Okta or Microsoft Entra |
| Decide which DOE workspace and role a person has | A DOE workspace admin manages this in DOE |
Automated user provisioning is also called SCIM. Auth0 and Google Workspace can be used for company sign-in, but they do not provide DOE's native automated user lifecycle in the current setup.
Company groups may be copied into DOE, but they do not currently assign DOE roles or permissions. Check workspace membership and role separately.
Prepare the rollout
- Confirm the company login service and work email domains.
- Name the company sign-in owner, DOE workspace admin, and Njord delivery contact.
- Decide whether people will be invited in DOE or added through supported automated provisioning.
- Choose a small pilot group.
- Test a new user, a returning user, a removed user, and a reactivated user.
- Confirm the DOE workspace and role after every access change.
Your company team configures its login service and account policies. Njord configures the DOE connection and domain mapping. Both teams test the complete sign-in before wider rollout.
First-time access
A person who signs in through company SSO for the first time normally needs a DOE invitation. When supported Okta or Microsoft Entra provisioning is enabled, an active company assignment can add the account without a separate invitation.
A successful company login does not choose a DOE workspace role. The DOE workspace admin remains responsible for membership and role.
Existing accounts
Use the same work email and sign-in method already connected to the DOE account. If DOE says the account already exists or cannot be matched, do not create a second account. Ask the Njord delivery team to check the existing account and company connection.
Add, remove, and reactivate people
With supported Okta or Microsoft Entra provisioning, assigning a person can add or reactivate the DOE account. Removing or deactivating the assignment should remove sign-in access and end active DOE sessions.
As part of offboarding tests, confirm that access is also removed from the expected DOE workspace and connected areas. If access remains anywhere, contact the DOE workspace admin and Njord delivery team.
Changing a company group does not by itself change a person's DOE role. After a person is reactivated, check the DOE workspace membership and role again.