SAML SSO

In diesem Hilfedokument

Notion provides Single Sign-On (SSO) functionality for Business and Enterprise customers to access the app through a single authentication source. This allows IT administrators to better manage team access and keeps information more secure.

Zu den FAQs

Hinweis: Diese Funktion steht nur Nutzer/-innen mit einem Business Plan oder Enterprise Plan zur Verfügung.

With SSO, you can streamline user management across systems, and remove the need for end-users to remember and manage multiple passwords by allowing them to sign in at one single access point and enjoy a seamless experience across multiple applications.

To use SSO with Notion:

  • Your workspace must be on a Business Plan or Enterprise Plan.

  • Your Identity Provider (IdP) must support the SAML 2.0 standard. See instructions for Identity Provider setup for specific apps here →

  • A workspace owner must configure SAML SSO for the Notion workspace.

  • At least one domain must be verified by a workspace owner. Learn more about domain verification →

Hinweis: Nur Workspace-Mitglieder können sich mit SAML SSO anmelden. Gäste, die zu Seiten in einem SAML-aktivierten Notion-Workspace eingeladen werden, können sich nicht mit SAML SSO anmelden. Stattdessen müssen sie eine andere Anmeldemethode verwenden, z. B. ihren Nutzernamen und ihr Passwort oder sich mit Google oder Apple anmelden.

Business Plan

To set up SAML SSO for a Business workspace, a workspace owner can:

  1. Go to SettingsGeneral.

  2. In the Allowed email domains section, remove all email domains.

  3. Select the Identity tab in Settings.

  4. Toggle on Enable SAML SSO and the SAML SSO Configuration modal will automatically appear and prompt you to complete the set-up.

  5. The SAML SSO Configuration modal is divided into two parts:

    • The Assertion Consumer Service (ACS) URL needs to be entered in your Identity Provider (IdP) portal.

    • The Identity Provider Details is a field in which you need to provide either an IdP URL or IdP metadata XML.

  6. Choose how people sign in and whether new accounts are created for them, then select Save & enable. You can make all of these choices before you save. You don’t need to save first and open the settings again.

Enterprise Plan

Enterprise Plan organization owners can manage SAML SSO for their workspace (or multiple workspaces belonging to their organization) by following these steps:

  1. Open the workspace switcher and select Manage organization. You may need to Set up organization first if you haven’t already. Learn more here →

  2. In the General tab of your organization settings, toggle on Enable SAML SSO.

  3. Choose a setup method (URL or metadata XML), paste the required information from your Identity Provider or IdP, and select Save & enable. You can also pick how people sign in and turn on automatic account creation before you save, so everything takes effect at once.

Hinweis: Derzeit können Organisationen mit Enterprise Plan SAML SSO nur mit einem IdP einrichten.

Once you have completed your configuration of SAML SSO for a workspace, members will be able to log in via SAML SSO in addition to other login methods, like username and password or Google authentication.

You can pick this while you are first setting up SAML, in the same save. You can also change it later.

If you want to ensure that members can log in using only SAML SSO and no other method, go to your SAML SSO settings and update the Login method to Only SAML SSO. Once this happens, workspace users will be logged out and required to log back in using SAML SSO. SAML SSO will only be enforced for members who use your verified domain.

On the Business Plan, this will look like this:

On the Enterprise Plan, this will look like this:

SSO bypass

In the event of IdP or SAML failure, certain users will be able to bypass SAML SSO by using their email and password credentials. They’ll be able to log in and disable or update their configuration.

  • If a SAML configuration is managed at the organization level, only organization owners will be able to bypass SSO.

  • If a SAML configuration is managed at the workspace level, only workspace owners will be able to bypass SSO.

Hinweis: Diese Funktion ist nur für Nutzer im Enterprise Plan verfügbar. Eine Domain-Verifizierung ist nicht erforderlich, um diese Funktion zu aktivieren.

Workspace-level SAML authorization allows enterprises to require SAML SSO for workspace access, regardless of a user's email domain. This enables safer external collaboration in your workspace.

To enable workspace-level SAML authorization:

  1. Open the workspace switcher and select Manage organization. You may need to Set up organization first if you haven’t already. Learn more here →

  2. In the General tab of your organization settings, toggle on Require SAML authorization for workspace access.

Hinweis: Bevor du diese Option aktivierst, stelle sicher, dass alle Mitglieder zu deinem Identitätsanbieter (IdP) hinzugefügt wurden, um zu verhindern, dass sie versehentlich aus deinem Workspace ausgeschlossen werden.

When enabled, members of the affected workspaces who haven’t already authorized with your organization’s IdP will be met with an additional authorization screen. They’ll need to go through SAML SSO to continue viewing your organization’s workspaces.

Notion supports Just-in-Time provisioning when using SAML SSO. This allows someone signing in via SAML SSO to join the workspace automatically as a member. You can turn this on while you set up SAML, in the same save.

To enable Just-in-Time provisioning if you're on the Business Plan, go to Settings Identity and make sure that Automatic account creation is enabled.

To enable Just-in-Time provisioning if you’re on the Enterprise Plan, go to your organization settings → General and make sure that Automatic account creation is enabled.

Hinweis: Bei Verwendung von SCIM ist die Just-in-Time-Bereitstellung nicht empfehlenswert. Über „zulässige E-Mail-Domains“ können Personen, die diese Domain nutzen, dem Workspace beitreten. Dadurch kann es zu Diskrepanzen zwischen den Mitgliedschaften bei den Identitätsanbietern und Notion kommen.


FAQs

Warum kann ich SAML SSO nicht aktivieren?

Der häufigste Grund ist, dass du den Besitz einer Domain noch nicht verifiziert hast. Wenn dies der Fall ist, wirst du feststellen, dass entweder keine Domains im Abschnitt „E-Mail-Domain verifizieren“ aufgeführt sind oder die Domain noch nicht verifiziert wurde.

Warum können die SAML-SSO-Einstellungen nicht bearbeitet werden?

Möglicherweise versuchst du, die verifizierten Domains oder die SSO-Konfiguration von einem verlinkten Workspace aus zu ändern, der bereits mit einer anderen SSO-Konfiguration verknüpft ist.

In verlinkten Workspaces sind alle Einstellungen rund um Domainverwaltung und SSO-Konfiguration schreibgeschützt. Um die SSO-Konfiguration zu ändern oder diesen Workspace aus der SSO-Konfiguration zu entfernen, ist ein Zugriff auf den primären Workspace erforderlich. Der Name des primären Workspaces befindet sich oben im Tab Identity & Bereitstellungin deinen Einstellungen.

Wieso müssen Domains vor der SSO-Aktivierung bestätigt werden?

Die Inhaberschaft der E-Mail-Domain muss überprüft werden, damit ausschließlich der tatsächliche Domaininhaber/-innen das Anmeldeverfahren verändern kann.

Ich habe Schwierigkeiten bei der Einrichtung von SSO.

  • Verwendung einer URL anstelle einer XML-Datei.

  • Teste den Einrichtungsprozess mit einem Testkonto, bevor du ihn für Nutzer/-innen erzwingst.

  • Wenn beides zu keiner Lösung führt, erreichst du unseren Support unter

Wieso soll man die unter „Zulässige E-Mail-Domains“ aufgeführten Domains entfernen, bevor man SAML SSO einrichten kann?

Die Einstellung Zulässige E-Mail-Domäne ermöglicht es Nutzer/-innen mit den ausgewählten Domänen, auf deinen Workspace zuzugreifen, ohne über deinen IdP bereitgestellt zu werden. Um sicherzustellen, dass nur Nutzer/-innen, die über deinen IdP bereitgestellt wurden, auf deinen SAML-fähigen Workspace zugreifen können, deaktiviere diese Funktion, indem du alle E-Mail-Adressen aus der Liste Zulässige E-Mail-Domäne entfernst.

Kann ich mich immer noch bei Notion anmelden, wenn mein Identitätsanbieter (IdP) derzeit nicht verfügbar ist?

Ja, selbst wenn SAML erzwungen wird, haben Workspace-Besitzer/-innen die Möglichkeit, sich mit ihrer E-Mail-Adresse anzumelden. Workspace-Besitzer/-innen können die SAML-Konfiguration ändern, um SAML erzwingen zu deaktivieren, damit sich Nutzer/-innen wieder mit E-Mail anmelden können.

Wie ermögliche ich es Admins anderer Workspaces in meiner SAML-Konfiguration, neue Workspaces zu erstellen?

Nur die Admins deines primären Workspaces können neue Workspaces mithilfe deiner verifizierten Domain(s) erstellen. Bitte wende dich an unseren Support (team@makenotion.com), um deinen primären SAML-Workspace in deiner SAML-Konfiguration auf eine andere verlinkte Workspace umzustellen.

Do I have to save my SAML settings twice?

No. You can add your provider details, pick how people sign in, and choose whether new accounts are created, then save once. Everything takes effect together.

Hast du noch Fragen? Sende eine Nachricht an den Support

Feedback geben

War diese Ressource hilfreich?