The shared setup workflow
1
Get Clumio's service-provider details
In the Clumio dashboard, open the SSO configuration and copy the Assertion Consumer Service URL
and Entity ID. Download the service-provider metadata file if your identity provider accepts one.
2
Configure the identity provider
Create or configure the Clumio SAML application in the identity provider. Add Clumio’s Entity ID,
Assertion Consumer Service URL, and required email claim. The exact field names differ by provider.
3
Add the identity-provider metadata to Clumio
Return to Clumio and provide the identity-provider metadata URL, XML file, or manual SAML
configuration supported by that provider.
4
Test before enabling SSO
Test the configuration with an administrator account before enabling SSO for other users. Keep a
recovery path available until the login has been confirmed.
Provider guides
Automatic user provisioning
Clumio documents group-based user provisioning for Okta and Microsoft Entra ID. Administrators map identity-provider groups to Clumio roles and organisational units, then enable auto user provisioning in Administration > Access Management > Auto user provisioning.Provision users with Okta
Configure group claims and map Okta groups to Clumio access rules.
Provision users with Microsoft Entra ID
Configure group claims and map Entra ID groups to Clumio access rules.
Authentication and authorisation remain separate. SSO confirms the user’s identity. Clumio roles and
organisational units determine what that user can access.