Single sign-on (SAML)
Let agents sign in to DeskAI through your identity provider: Microsoft Entra ID, Okta, Google Workspace, OneLogin or any SAML 2.0 provider. Available on the Business and Enterprise plans.
Set up the connection
- In DeskAI, go to Admin Portal → Security → Single sign-on (SAML). Enter your email domain (for example
deskyon.example) and save. - DeskAI shows an Identifier (Entity ID), a Reply URL and a Metadata URL. In your identity provider, create a SAML app with those values. In Microsoft Entra ID that is Enterprise applications → New application → Create your own application, then Single sign-on → SAML.
- Send the person’s email address as the Name ID, or as an
emailclaim. - Copy the identity provider’s Entity ID (in Entra: Microsoft Entra Identifier), its sign-in URL (Login URL) and its signing certificate (Base64) into DeskAI.
- Turn on Allow SSO sign-in, save, and use Test sign-in.
Signing in
On the sign-in page, people enter their work email and choose Sign in with SSO. DeskAI finds the connection for their email domain and sends them to your identity provider.
Options
- Require SSO: passwords, Google and Microsoft sign-in stop working for your domains. MSP admins can always still sign in another way, so a broken identity provider can’t lock everyone out.
- Create accounts on first sign-in: anyone your identity provider lets in gets an agent account in your company, up to your plan’s technician limit. When it’s off, only people who already have a DeskAI account can sign in.
Safeguards
- Only signed assertions from your identity provider’s certificate are accepted, for this connection’s audience, while they are still valid, and each one only once.
- A connection only signs in emails on its own domains, and only people in its own company. A company can only claim a domain its technicians already use, and each domain belongs to one connection.
- Sign-ins, refused sign-ins and changes to the connection are listed under Admin Portal → Audit Log → Security events.