NineID supports SAML 2.0 Single Sign-On (SSO), allowing users to log in with their organizationâs identity provider (such as Azure AD, Okta, or any SAML-compatible provider) instead of using a separate username and password.
đ Where to Find It
Go to:
âConfiguration â Integrations â SAML SSO
⨠Key Features
Automatic User Provisioning
New users can be automatically created the first time they log in via SSO.Default Role Assignment
Assign a default role to newly provisioned users.Group-to-Role Mapping
Map identity provider groups to NineID roles
â(Example: âManagersâ group â âSite Managerâ role).Strict Roles Mode
When enabled, user roles are fully synchronized from the identity provider at every login.
đ¤ How It Works for Users
Once SSO is configured, users will see a âLogin with SSOâ button on the NineID login page.
Click Login with SSO
Authenticate via your organizationâs identity provider
Return to NineID automatically logged in â
đ Required Attributes from the Identity Provider
The following attributes must be provided:
firstNamelastNameemailphone(optional)Groups(optional, required for role mapping)
âď¸ Identity Provider Configuration Details
The Integrations page provides the technical information required to configure your identity provider, including:
Entity ID
Callback (ACS) URLs
Additional SAML configuration details
Use these values in your identity providerâs admin console to complete the setup.



