Skip to content
Admin & Security

How to set up Single Sign-On (SSO) in HelloGrowthCRM

Configure SAML 2.0 or OIDC SSO with Okta, Google Workspace, Azure AD, OneLogin. Just-in-time provisioning included.

25 min readUpdated 12 Jun 2026
advanced
Harnish ShahHarnish Shah

What this guide helps you do

Follow this article when you want a focused, step-by-step path to complete the task without digging through menus.

Need a broader overview first?

Go back to the Admin & Security section to browse more guides, compare related tasks, and choose a better starting point.

View all Admin & Security guides

SSO eliminates password sprawl. SAML/OIDC. SCIM auto-provisioning means new hires get CRM access on day one.

How to use this guide

Read the intro to confirm this is the right workflow, complete the steps in order, then review the common issues and related articles if your setup behaves differently from the standard path.

What you'll need

  • Enterprise tier
  • IdP admin access
  • HelloGrowthCRM Owner role
  • 30-60 minutes
  1. 1

    Settings → Security → SSO

    Settings → Security → SSO.

  2. 2

    Pick protocol

    SAML 2.0 (most common) or OIDC (modern).

  3. 3

    Get HelloGrowthCRM SAML/OIDC details

    ACS URL, SP Entity ID, certificate.

  4. 4

    Configure IdP

    Okta/Azure/Google: create SAML app, paste our endpoints.

  5. 5

    Get IdP metadata

    IdP gives SSO URL + certificate.

  6. 6

    Paste into HelloGrowthCRM

    Settings → SSO → IdP config.

  7. 7

    Map attributes

    email, first_name, last_name, role.

  8. 8

    Enable JIT provisioning

    New users auto-create on first login.

  9. 9

    Configure SCIM

    IdP pushes user create/update/disable to CRM.

  10. 10

    Test

    User signs in via IdP. Lands in CRM. Verify role mapped.

  11. 11

    Enforce

    Disable password login. SSO-only enforced.

Frequently asked questions

Multiple IdPs?

Yes — different domains can route to different IdPs.

SCIM for which IdPs?

Okta, Azure AD, OneLogin, Google Workspace.

MFA at IdP or CRM?

Both work; IdP MFA usually preferred.

Audit log SSO?

Yes — every SSO login logs.

Disable user via IdP?

SCIM auto-deactivates in CRM.

Cost?

Enterprise feature; included.

Related articles

See it in product

Try it yourself

Start a 14-day free trial of HelloGrowthCRM — no credit card required. You'll have everything you need to follow this guide.

Still need help?

If this article does not match your account setup, rollout stage, or edge case, review more guides in Admin & Security or contact our team for direct help.

Harnish Shah
Harnish Shah· Co-Founder, HelloGrowthCRM

Harnish leads engineering at HelloGrowthCRM. He focuses on CRM architecture, AI agents, and integrations across calling, messaging, and revenue systems.

Connect on LinkedIn →