Enterprise SSO for company access

Company SSO sign-in option on the DOE sign-in screen

Highlights

  • New: Users can choose Sign in with SSO and continue through their company's login service.
  • Security: The company identity provider keeps control of passwords, MFA and account status.
  • Improved: DOE keeps workspace invitations, membership and roles separate from company sign-in.
  • Admin: Supported Okta and Microsoft Entra provisioning can add, deactivate and reactivate company-managed users.

What changed

Enterprise SSO gives organizations one company-managed way to enter DOE. The user signs in through the identity provider their organization already trusts, while DOE checks whether that person can enter the requested workspace.

This separation makes responsibility clearer: the company manages identity and security checks, and the DOE workspace admin manages membership and role.

Sign in with company SSO

  1. Open the DOE sign-in page.
  2. Choose Sign in with SSO.
  3. Enter your work email when asked.
  4. Complete your company's login and MFA checks.
  5. Return to DOE.

If company login succeeds but DOE does not open the expected workspace, ask the DOE workspace admin to check the exact email, membership and role.

Who manages access?

AreaMain responsibility
Company account, password and MFAYour company sign-in team
Enterprise SSO connectionYour company sign-in team and Njord set up and test their respective sides
DOE invitation, workspace membership and roleYour DOE workspace admin
Personal profile detailsThe signed-in person, within the fields DOE allows them to edit

Resetting a DOE password does not change a company password, bypass company MFA or reactivate a disabled company account.

First-time and administrator-managed access

People who enter through company SSO for the first time normally need a DOE workspace invitation. With supported Okta or Microsoft Entra provisioning, an active company assignment can add the account without a separate invitation.

Company groups do not currently choose DOE roles. Workspace admins should check membership and role separately during onboarding, offboarding and reactivation.

If sign-in does not work

What happensWhat to do
The company login page blocks accessContact your company sign-in team
DOE cannot find a company connectionCheck the work email, then ask your company sign-in admin or Njord delivery contact to check setup
DOE asks for an invitationAsk your DOE workspace admin to check the exact work email and access method
Company login succeeds but DOE blocks accessAsk your DOE workspace admin to check membership and role
DOE says the account already existsUse the sign-in method already connected to the account; do not create a second account
A removed or returning person has the wrong accessAsk both the company sign-in admin and DOE workspace admin to check the account

Related guides