Single Sign-On

Connect your identity provider (IdP) to CloudZero to enable single sign-on (SSO). SSO lets your users log in to CloudZero from their IdP without needing a separate CloudZero username and password.

SSO integrations are managed in Settings > SSO Integrations.

SSO Integrations page in Settings

Choose your identity provider

CloudZero supports OIDC and SAML 2.0. If your IdP supports both and your organization does not require a specific protocol, OIDC is simpler to configure.

Identity providerProtocolGuide
GoogleOIDCSet Up SSO with OpenID Connect
Microsoft Entra ID (Azure AD)OIDCSet Up SSO with Microsoft Entra ID
OktaOIDC or SAMLSet Up SSO with Okta (OIDC) or SAML
OneLoginOIDC or SAMLSet Up SSO with OpenID Connect or SAML
Ping IdentityOIDC or SAMLSet Up SSO with OpenID Connect or SAML
Other OIDC providerOIDCSet Up SSO with OpenID Connect
Other SAML 2.0 providerSAMLSet Up SSO with SAML

To have your IdP automatically manage CloudZero Role assignments, see Manage Roles with SSO.

To delete an existing SSO integration, see Delete an SSO Integration.

ℹ️

If any users in your organization have installed the VS Code Extension, they must re-authenticate with CloudZero after changes to your SSO configuration.

ℹ️

Have questions or feedback? Reach out to your account manager.