Skip to main content
Clumio documents SAML setup separately for nine identity providers. This page demonstrates how one maintained hub could explain the shared workflow and route administrators to provider-specific steps.
This is an information-architecture prototype. Use the linked Clumio guides for current production instructions.

The shared setup workflow

1

Get Clumio's service-provider details

In the Clumio dashboard, open the SSO configuration and copy the Assertion Consumer Service URL and Entity ID. Download the service-provider metadata file if your identity provider accepts one.
2

Configure the identity provider

Create or configure the Clumio SAML application in the identity provider. Add Clumio’s Entity ID, Assertion Consumer Service URL, and required email claim. The exact field names differ by provider.
3

Add the identity-provider metadata to Clumio

Return to Clumio and provide the identity-provider metadata URL, XML file, or manual SAML configuration supported by that provider.
4

Test before enabling SSO

Test the configuration with an administrator account before enabling SSO for other users. Keep a recovery path available until the login has been confirmed.

Provider guides

Automatic user provisioning

Clumio documents group-based user provisioning for Okta and Microsoft Entra ID. Administrators map identity-provider groups to Clumio roles and organisational units, then enable auto user provisioning in Administration > Access Management > Auto user provisioning.

Provision users with Okta

Configure group claims and map Okta groups to Clumio access rules.

Provision users with Microsoft Entra ID

Configure group claims and map Entra ID groups to Clumio access rules.
Authentication and authorisation remain separate. SSO confirms the user’s identity. Clumio roles and organisational units determine what that user can access.