Enterprise SSO for company access

Highlights
- New: Users can choose Sign in with SSO and continue through their company's login service.
- Security: The company identity provider keeps control of passwords, MFA and account status.
- Improved: DOE keeps workspace invitations, membership and roles separate from company sign-in.
- Admin: Supported Okta and Microsoft Entra provisioning can add, deactivate and reactivate company-managed users.
What changed
Enterprise SSO gives organizations one company-managed way to enter DOE. The user signs in through the identity provider their organization already trusts, while DOE checks whether that person can enter the requested workspace.
This separation makes responsibility clearer: the company manages identity and security checks, and the DOE workspace admin manages membership and role.
Sign in with company SSO
- Open the DOE sign-in page.
- Choose Sign in with SSO.
- Enter your work email when asked.
- Complete your company's login and MFA checks.
- Return to DOE.
If company login succeeds but DOE does not open the expected workspace, ask the DOE workspace admin to check the exact email, membership and role.
Who manages access?
| Area | Main responsibility |
|---|---|
| Company account, password and MFA | Your company sign-in team |
| Enterprise SSO connection | Your company sign-in team and Njord set up and test their respective sides |
| DOE invitation, workspace membership and role | Your DOE workspace admin |
| Personal profile details | The signed-in person, within the fields DOE allows them to edit |
Resetting a DOE password does not change a company password, bypass company MFA or reactivate a disabled company account.
First-time and administrator-managed access
People who enter through company SSO for the first time normally need a DOE workspace invitation. With supported Okta or Microsoft Entra provisioning, an active company assignment can add the account without a separate invitation.
Company groups do not currently choose DOE roles. Workspace admins should check membership and role separately during onboarding, offboarding and reactivation.
If sign-in does not work
| What happens | What to do |
|---|---|
| The company login page blocks access | Contact your company sign-in team |
| DOE cannot find a company connection | Check the work email, then ask your company sign-in admin or Njord delivery contact to check setup |
| DOE asks for an invitation | Ask your DOE workspace admin to check the exact work email and access method |
| Company login succeeds but DOE blocks access | Ask your DOE workspace admin to check membership and role |
| DOE says the account already exists | Use the sign-in method already connected to the account; do not create a second account |
| A removed or returning person has the wrong access | Ask both the company sign-in admin and DOE workspace admin to check the account |