SAML SSO

في مستند المساعدة هذا

Notion provides Single Sign-On (SSO) functionality for Business and Enterprise customers to access the app through a single authentication source. This allows IT administrators to better manage team access and keeps information more secure.

الانتقال إلى الأسئلة الشائعة

ملاحظة: هذه الميزة متوفرة فقط للمستخدمين في خطة الأعمال أو الخطة المؤسسية.

With SSO, you can streamline user management across systems, and remove the need for end-users to remember and manage multiple passwords by allowing them to sign in at one single access point and enjoy a seamless experience across multiple applications.

To use SSO with Notion:

  • Your workspace must be on a Business Plan or Enterprise Plan.

  • Your Identity Provider (IdP) must support the SAML 2.0 standard. See instructions for Identity Provider setup for specific apps here →

  • A workspace owner must configure SAML SSO for the Notion workspace.

  • At least one domain must be verified by a workspace owner. Learn more about domain verification →

ملاحظة: يمكن لأعضاء مساحة العمل فقط استخدام تسجيل الدخول الأحادي عبر بروتوكول SAML لتسجيل الدخول. لا يمكن للضيوف المدعوين إلى صفحات في مساحة عمل Notion التي تدعم SAML تسجيل الدخول باستخدام تسجيل الدخول الأحادي عبر بروتوكول SAML. بدلاً من ذلك، سيحتاجون إلى استخدام طريقة تسجيل دخول أخرى، مثل اسم المستخدم وكلمة المرور أو تسجيل الدخول باستخدام Google أو Apple.

Business Plan

To set up SAML SSO for a Business workspace, a workspace owner can:

  1. Go to SettingsGeneral.

  2. In the Allowed email domains section, remove all email domains.

  3. Select the Identity tab in Settings.

  4. Toggle on Enable SAML SSO and the SAML SSO Configuration modal will automatically appear and prompt you to complete the set-up.

  5. The SAML SSO Configuration modal is divided into two parts:

    • The Assertion Consumer Service (ACS) URL needs to be entered in your Identity Provider (IdP) portal.

    • The Identity Provider Details is a field in which you need to provide either an IdP URL or IdP metadata XML.

  6. Choose how people sign in and whether new accounts are created for them, then select Save & enable. You can make all of these choices before you save. You don’t need to save first and open the settings again.

Enterprise Plan

Enterprise Plan organization owners can manage SAML SSO for their workspace (or multiple workspaces belonging to their organization) by following these steps:

  1. Open the workspace switcher and select Manage organization. You may need to Set up organization first if you haven’t already. Learn more here →

  2. In the General tab of your organization settings, toggle on Enable SAML SSO.

  3. Choose a setup method (URL or metadata XML), paste the required information from your Identity Provider or IdP, and select Save & enable. You can also pick how people sign in and turn on automatic account creation before you save, so everything takes effect at once.

ملاحظة: في الوقت الحالي، يمكن للمؤسسات على الخطة المؤسسية إعداد تسجيل الدخول الموحد (SAML SSO) مع مزود هوية واحد فقط.

Once you have completed your configuration of SAML SSO for a workspace, members will be able to log in via SAML SSO in addition to other login methods, like username and password or Google authentication.

You can pick this while you are first setting up SAML, in the same save. You can also change it later.

If you want to ensure that members can log in using only SAML SSO and no other method, go to your SAML SSO settings and update the Login method to Only SAML SSO. Once this happens, workspace users will be logged out and required to log back in using SAML SSO. SAML SSO will only be enforced for members who use your verified domain.

On the Business Plan, this will look like this:

On the Enterprise Plan, this will look like this:

SSO bypass

In the event of IdP or SAML failure, certain users will be able to bypass SAML SSO by using their email and password credentials. They’ll be able to log in and disable or update their configuration.

  • If a SAML configuration is managed at the organization level, only organization owners will be able to bypass SSO.

  • If a SAML configuration is managed at the workspace level, only workspace owners will be able to bypass SSO.

ملاحظة: هذه الميزة متاحة فقط للمستخدمين المشتركين في الخطة المؤسسية. لا يلزم التحقق من النطاق لتمكين هذه الميزة.

Workspace-level SAML authorization allows enterprises to require SAML SSO for workspace access, regardless of a user's email domain. This enables safer external collaboration in your workspace.

To enable workspace-level SAML authorization:

  1. Open the workspace switcher and select Manage organization. You may need to Set up organization first if you haven’t already. Learn more here →

  2. In the General tab of your organization settings, toggle on Require SAML authorization for workspace access.

ملاحظة: قبل التمكين، تأكد من إضافة جميع الأعضاء إلى موفر الهوية (IdP) الخاص بك لمنع حدوث عمليات قفل غير مقصودة من مساحة العمل.

When enabled, members of the affected workspaces who haven’t already authorized with your organization’s IdP will be met with an additional authorization screen. They’ll need to go through SAML SSO to continue viewing your organization’s workspaces.

Notion supports Just-in-Time provisioning when using SAML SSO. This allows someone signing in via SAML SSO to join the workspace automatically as a member. You can turn this on while you set up SAML, in the same save.

To enable Just-in-Time provisioning if you're on the Business Plan, go to Settings Identity and make sure that Automatic account creation is enabled.

To enable Just-in-Time provisioning if you’re on the Enterprise Plan, go to your organization settings → General and make sure that Automatic account creation is enabled.

ملاحظة: لا نوصي بتمكين التزويد في الوقت المناسب (Just-in Time provisioning) إذا كنت تستخدم SCIM. وجود "نطاق بريد إلكتروني مسموح به" يسمح للمستخدمين في هذا النطاق بالانضمام إلى مساحة العمل، مما قد يؤدي إلى عدم تطابق بين العضوية في موفري الهوية لديهم وNotion.


الأسئلة الشائعة

لماذا لا يمكنني تمكين تسجيل الدخول الأحادي عبر بروتوكول SAML؟

لماذا لا يمكنني تعديل إعدادات تسجيل الدخول الأحادي عبر بروتوكول SAML الخاصة بي؟

من المحتمل أنك تحاول تعديل النطاقات التي تم التحقق منها أو تكوين تسجيل الدخول الأحادي من مساحة عمل مرتبطة مقترنة بالفعل بتكوين آخر لتسجيل الدخول الأحادي.

في مساحات العمل المرتبطة، تكون جميع إعدادات إدارة النطاق وتكوين تسجيل الدخول الأحادي للقراءة فقط. لتعديل تكوين تسجيل الدخول الأحادي أو إزالة مساحة العمل هذه من تكوين تسجيل الدخول الأحادي، يجب أن يكون لديك حق الوصول إلى مساحة العمل الأساسية. يمكن العثور على اسم مساحة العمل الأساسية في أعلى علامة التبويب الهوية والتزويد في إعداداتك.

لماذا أحتاج إلى التحقق من نطاق لتمكين تسجيل الدخول الأحادي؟

نحن نطلب التحقق من ملكية نطاق البريد الإلكتروني لضمان أن مالك النطاق فقط هو من يمكنه تخصيص كيفية تسجيل مستخدميه للدخول إلى Notion.

أواجه مشكلة في إعداد تسجيل الدخول الموحد (SSO).

  • جرب استخدام رابط (URL) بدلاً من ملف XML.

  • اختبر عملية الإعداد باستخدام حساب تجريبي قبل فرضها على المستخدمين.

  • إذا لم يساعدك أي من هذين الخيارين، فتواصل مع فريق الدعم على

لماذا ينبغي علي إزالة نطاقات البريد الإلكتروني من إعداد "نطاقات البريد الإلكتروني المسموح بها" قبل تكوين تسجيل الدخول الموحد (SAML SSO) لمساحة عمل الخاصة بي؟

يسمح إعداد نطاق البريد الإلكتروني المسموح به للمستخدمين الذين لديهم النطاقات المحددة بالوصول إلى مساحة عمل الخاصة بك دون أن يتم توفير حساباتهم عبر مزود الهوية (IdP) الخاص بك. ولضمان أن المستخدمين الذين تم توفير حساباتهم عبر مزود الهوية فقط يمكنهم الوصول إلى مساحة عمل المفعلة لـ SAML، قم بتعطيل هذه الخاصية عن طريق إزالة جميع عناوين البريد الإلكتروني من قائمة نطاق البريد الإلكتروني المسموح به.

هل لا يزال بإمكاني تسجيل الدخول إلى Notion إذا كان موفر الهوية (IdP) الخاص بي خارج الخدمة؟

نعم، حتى مع فرض SAML، يمتلك مالكو مساحة العمل خيار تسجيل الدخول عبر البريد الإلكتروني. يمكن لمالك مساحة العمل تغيير إعدادات SAML لتعطيل فرض SAML حتى يتمكن المستخدمون من تسجيل الدخول عبر البريد الإلكتروني مرة أخرى.

كيف يمكنني السماح لمسؤولي مساحات عمل الأخرى في تكوين SAML الخاص بي بإنشاء مساحات عمل جديدة؟

سيتمكن مسؤولو مساحة عمل الأساسية الخاصة بك فقط من إنشاء مساحات عمل جديدة باستخدام النطاق (النطاقات) الذي تم التحقق منه. يرجى التواصل مع فريق الدعم لدينا (team@makenotion.com) لتحويل مساحة عمل SAML الأساسية الخاصة بك إلى مساحة عمل أخرى مرتبطة في تكوين SAML الخاص بك.

Do I have to save my SAML settings twice?

No. You can add your provider details, pick how people sign in, and choose whether new accounts are created, then save once. Everything takes effect together.

هل لديك المزيد من الأسئلة؟ راسل الدعم

تقديم تعليق

هل كان هذا المورد مفيداً؟