SAML SSO

このヘルプドキュメント内

Notion provides Single Sign-On (SSO) functionality for Business and Enterprise customers to access the app through a single authentication source. This allows IT administrators to better manage team access and keeps information more secure.

よくあるご質問(FAQ)に移動

注:この機能は、ビジネスプランまたはエンタープライズプランのユーザーのみが利用できます。

With SSO, you can streamline user management across systems, and remove the need for end-users to remember and manage multiple passwords by allowing them to sign in at one single access point and enjoy a seamless experience across multiple applications.

To use SSO with Notion:

  • Your workspace must be on a Business Plan or Enterprise Plan.

  • Your Identity Provider (IdP) must support the SAML 2.0 standard. See instructions for Identity Provider setup for specific apps here →

  • A workspace owner must configure SAML SSO for the Notion workspace.

  • At least one domain must be verified by a workspace owner. Learn more about domain verification →

備考: ワークスペースのメンバーのみが、SAML SSOを使用してログインできます。SAMLを有効にしているNotionワークスペースのページに招待されているゲストは、SAML SSOでログインすることはできません。代わりに、ユーザー名/パスワードまたはGoogleやAppleでのログインなど、別のログイン方法を使う必要があります。

Business Plan

To set up SAML SSO for a Business workspace, a workspace owner can:

  1. Go to SettingsGeneral.

  2. In the Allowed email domains section, remove all email domains.

  3. Select the Identity tab in Settings.

  4. Toggle on Enable SAML SSO and the SAML SSO Configuration modal will automatically appear and prompt you to complete the set-up.

  5. The SAML SSO Configuration modal is divided into two parts:

    • The Assertion Consumer Service (ACS) URL needs to be entered in your Identity Provider (IdP) portal.

    • The Identity Provider Details is a field in which you need to provide either an IdP URL or IdP metadata XML.

  6. Choose how people sign in and whether new accounts are created for them, then select Save & enable. You can make all of these choices before you save. You don’t need to save first and open the settings again.

Enterprise Plan

Enterprise Plan organization owners can manage SAML SSO for their workspace (or multiple workspaces belonging to their organization) by following these steps:

  1. Open the workspace switcher and select Manage organization. You may need to Set up organization first if you haven’t already. Learn more here →

  2. In the General tab of your organization settings, toggle on Enable SAML SSO.

  3. Choose a setup method (URL or metadata XML), paste the required information from your Identity Provider or IdP, and select Save & enable. You can also pick how people sign in and turn on automatic account creation before you save, so everything takes effect at once.

備考:現時点では、エンタープライズプランの組織は1つのIdPでのみSAML SSOを設定できます。

Once you have completed your configuration of SAML SSO for a workspace, members will be able to log in via SAML SSO in addition to other login methods, like username and password or Google authentication.

You can pick this while you are first setting up SAML, in the same save. You can also change it later.

If you want to ensure that members can log in using only SAML SSO and no other method, go to your SAML SSO settings and update the Login method to Only SAML SSO. Once this happens, workspace users will be logged out and required to log back in using SAML SSO. SAML SSO will only be enforced for members who use your verified domain.

On the Business Plan, this will look like this:

On the Enterprise Plan, this will look like this:

SSO bypass

In the event of IdP or SAML failure, certain users will be able to bypass SAML SSO by using their email and password credentials. They’ll be able to log in and disable or update their configuration.

  • If a SAML configuration is managed at the organization level, only organization owners will be able to bypass SSO.

  • If a SAML configuration is managed at the workspace level, only workspace owners will be able to bypass SSO.

備考: この機能は、エンタープライズプランをご利用のユーザーのみが利用可能です。この機能を有効にするためには、ドメイン検証は必要ありません。

Workspace-level SAML authorization allows enterprises to require SAML SSO for workspace access, regardless of a user's email domain. This enables safer external collaboration in your workspace.

To enable workspace-level SAML authorization:

  1. Open the workspace switcher and select Manage organization. You may need to Set up organization first if you haven’t already. Learn more here →

  2. In the General tab of your organization settings, toggle on Require SAML authorization for workspace access.

備考:有効にする前に、すべてのメンバーが ID プロバイダー(IdP)に追加されていることを確認して、ワークスペースから誤ってロックアウトされないようにしてください。

When enabled, members of the affected workspaces who haven’t already authorized with your organization’s IdP will be met with an additional authorization screen. They’ll need to go through SAML SSO to continue viewing your organization’s workspaces.

Notion supports Just-in-Time provisioning when using SAML SSO. This allows someone signing in via SAML SSO to join the workspace automatically as a member. You can turn this on while you set up SAML, in the same save.

To enable Just-in-Time provisioning if you're on the Business Plan, go to Settings Identity and make sure that Automatic account creation is enabled.

To enable Just-in-Time provisioning if you’re on the Enterprise Plan, go to your organization settings → General and make sure that Automatic account creation is enabled.

備考: SCIMを使用している場合は、ジャストインタイム(JIT)プロビジョニングを有効にすることは推奨されません。「許可されているメールドメイン」を設定すると、そのドメインのユーザーがワークスペースに参加できるようになるため、IDプロバイダーとNotionのメンバーシップが一致しなくなる可能性があります。


よくあるご質問(FAQ)

SAML SSOを有効にできないのはなぜですか?

最もよくある理由として、ドメインの所有権がまだ検証されていないことが考えられます。検証されていない場合、検証済みメールドメインのセクションにドメインが表示されていないか、ドメインの検証が保留中となっているはずです。

SAML SSO設定を変更できないのはなぜですか?

すでに別のSSO設定に関連付けられている/リンクドワークスペースから、検証済みのドメインまたはSSO設定を変更しようとしている可能性があります。

リンクドワークスペースでは、ドメイン管理とSSO設定は読み取り専用です。SSO設定を変更したり、SSO設定からこのワークスペースを削除するには、メインワークスペースにアクセスする必要があります。メインワークスペースの名前は、設定のアイデンティティとプロビジョニングタブの上部にあります。

SSOを有効にするために、なぜドメインを検証する必要があるのですか?

メールドメインの所有権の検証をお願いしているのは、ドメインの所有者のみがユーザーのNotionへのログイン方法をカスタマイズできるようにするためです。

SSOの設定がうまくいきません。

  • XMLの代わりにURLを使用してみてください。

  • ユーザーに対して強制する前に、テストアカウントを使用して設定プロセスをテストします。

  • 上記のどちらでも解決しない場合は、

    サポート(team@makenotion.com)にお問い合わせください。

ワークスペースのSAML SSOを設定する前に、「許可されているメールドメイン」からメールドメインを削除する必要があるのはなぜですか?

許可されているメールドメインの設定により、選択したドメインを持つユーザーは、IdP経由でプロビジョニングされることなくワークスペースへのアクセスできてしまいます。ですから、IdP経由でプロビジョニングされたユーザーのみがSAML有効なワークスペースにアクセスできるようにするために、許可されているメールドメインリストからすべてのメールアドレスを削除して、この機能を無効にします。

利用しているIDプロバイダー(IdP)がサービス停止している場合でもNotionにログインできますか?

はい。SAMLが強制されている場合も、ワークスペースオーナーには、メールでログインできます。ワークスペースオーナーは、ユーザーがメールで再びログインできるように、SAML強制設定を無効にできます。

SAML設定内の他のワークスペースの管理者に新しいワークスペースの作成を許可するにはどうすればよいですか?

メインのワークスペースの管理者のみが、検証済みのドメインを使用して新しいワークスペースを作成できます。メインのSAMLワークスペースを、SAML設定内の別のリンクされたワークスペースに切り替える際は、サポートチーム(team@makenotion.com)までご依頼ください。

Do I have to save my SAML settings twice?

No. You can add your provider details, pick how people sign in, and choose whether new accounts are created, then save once. Everything takes effect together.

さらにご質問がある場合は、サポートにメッセージを送信してください

フィードバックを送信

このコンテンツは役に立ちましたか?