Overview
Enterprise SSO lets Members sign in to a Plaud Team workspace with their organization's identity provider instead of a Plaud password. This article covers how Admins set it up and what Members should expect when they sign in.
What is Enterprise SSO?
Enterprise SSO is a sign-in method for Plaud Team that connects your workspace to your organization's identity provider, such as Okta or Microsoft Entra. Members authenticate with their company credentials, and Plaud never sees or stores their IdP password.
Enterprise SSO is included with every Plaud Team subscription at no extra cost. It's available on Plaud Web and the Plaud Mobile App.
How does an Admin set up Enterprise SSO?
An Admin turns on Enterprise SSO from the Team workspace's Security settings, in the SSO panel, and completes three steps in order:
- Enable Enterprise SSO. This starts the setup and makes the next two steps available.
- Verify your domain. Submit your company domain in the SSO panel. Plaud checks the domain's eligibility automatically, then hands off to a hosted verification page where your IT team adds a DNS record to prove domain ownership. Once the record is in place, wait for Plaud to confirm the domain is uniquely yours. This step can take anywhere from a few hours to a few days, depending on how quickly your IT team updates DNS.
- Configure your identity provider. Once the domain is verified, the Admin connects the workspace to the company's IdP using SAML or OIDC in the hosted configuration portal. The connection becomes active right after the setup completes.
Plaud recommends the Admin sign in with Enterprise SSO once after setup to confirm the connection works before requiring it for the whole workspace.
How do Members sign in with Enterprise SSO?
Members select Enterprise SSO on the sign-in screen and enter their work email. Plaud redirects them to the company's identity provider, and after they authenticate there, they're signed in to Plaud without ever entering a Plaud password.
If the Admin has invited the Member to the Team workspace, the invitation is accepted automatically during the Enterprise SSO sign-in, and they land in the Team workspace. If there's no invite yet, they still sign in successfully but land in a personal workspace only, with no visibility into the Team workspace. They can ask their Admin for an invite at any time.
What happens to my existing Plaud account when I sign in with Enterprise SSO?
If your work email already has a Plaud account, such as one created with a password or a social login, Enterprise SSO links to that account instead of creating a new one. Your existing recordings, notes, and preferences carry over.
To confirm the link, Plaud asks you to verify your identity by signing in once with that account's original method. If more than one Plaud account matches your email, you'll see a list of matches and choose the account you want to link before verifying.
Do I still need Plaud's two-factor authentication with Enterprise SSO?
No. Signing in with Enterprise SSO doesn't trigger Plaud's two-factor authentication, since your organization's identity provider handles its own sign-in security.
If you sign in to the same account with a password or a social login instead, Plaud's two-factor authentication still applies as usual.
Can an Admin require Enterprise SSO for the Team workspace?
Yes. An Admin can require that Members use Enterprise SSO to access the Team workspace. Once this is turned on, a Member signed in with a password or a social login is asked to sign in again with Enterprise SSO before they can open that Team workspace.
This requirement only affects the Team workspace it's set on. A Member's Personal workspace and any other Team workspaces stay accessible with their usual sign-in method.
Does Enterprise SSO add Members to my workspace automatically?
No. Enterprise SSO changes how people sign in, not who belongs to your workspace. It doesn't include SCIM or directory sync, so Plaud doesn't create, update, or remove accounts based on your organization's user directory. Joining a Team workspace still requires an Admin invitation, and removing someone still happens in Workspace management, the same as without Enterprise SSO.
What if Enterprise SSO isn't set up yet for my organization?
If you select Enterprise SSO but your organization hasn't set it up, Plaud lets you know it isn't available and takes you back to the standard sign-in options. You can still sign in with your Plaud password or a social login while you wait for your Admin to complete setup.
Still have questions?
Submit a request and our support team will get back to you within 24 hours on business days.