SAML SSO
Notion provides Single Sign-On (SSO) functionality for Business and Enterprise customers to access the app through a single authentication source. This allows IT administrators to better manage team access and keeps information more secure.
자주 묻는 질문(FAQ)으로 이동참고: 이 기능은 비즈니스 요금제 또는 엔터프라이즈 요금제 사용자만 사용할 수 있습니다.
With SSO, you can streamline user management across systems, and remove the need for end-users to remember and manage multiple passwords by allowing them to sign in at one single access point and enjoy a seamless experience across multiple applications.
To use SSO with Notion:
Your workspace must be on a Business Plan or Enterprise Plan.
Your Identity Provider (IdP) must support the SAML 2.0 standard. See instructions for Identity Provider setup for specific apps here →
A workspace owner must configure SAML SSO for the Notion workspace.
At least one domain must be verified by a workspace owner. Learn more about domain verification →
참고: 워크스페이스 멤버만 SAML SSO를 사용하여 로그인할 수 있습니다. SAML이 활성화된 Notion 워크스페이스의 페이지에 초대된 게스트는 SAML SSO로 로그인할 수 없습니다. 대신 사용자 이름과 비밀번호를 사용하거나 Google 계정 또는 Apple 계정으로 로그인하는 등 다른 로그인 수단을 사용해야 합니다.
Business Plan
To set up SAML SSO for a Business workspace, a workspace owner can:
Go to
Settings→General.In the
Allowed email domainssection, remove all email domains.Select the
Identitytab inSettings.
Verify one or more domains. See instructions for domain verification here →
Toggle on
Enable SAML SSOand the SAML SSO Configuration modal will automatically appear and prompt you to complete the set-up.The SAML SSO Configuration modal is divided into two parts:
The
Assertion Consumer Service (ACS) URLneeds to be entered in your Identity Provider (IdP) portal.The
Identity Provider Detailsis a field in which you need to provide either an IdP URL or IdP metadata XML.
Choose how people sign in and whether new accounts are created for them, then select
Save & enable. You can make all of these choices before you save. You don’t need to save first and open the settings again.

Enterprise Plan
Enterprise Plan organization owners can manage SAML SSO for their workspace (or multiple workspaces belonging to their organization) by following these steps:
Open the workspace switcher and select Manage organization. You may need to Set up organization first if you haven’t already. Learn more here →
In the
Generaltab of your organization settings, toggle onEnable SAML SSO.Choose a setup method (URL or metadata XML), paste the required information from your Identity Provider or IdP, and select
Save & enable. You can also pick how people sign in and turn on automatic account creation before you save, so everything takes effect at once.
참고: 현재 엔터프라이즈 요금제를 사용하는 조직은 하나의 IdP로만 SAML SSO를 설정할 수 있습니다.
Once you have completed your configuration of SAML SSO for a workspace, members will be able to log in via SAML SSO in addition to other login methods, like username and password or Google authentication.
You can pick this while you are first setting up SAML, in the same save. You can also change it later.
If you want to ensure that members can log in using only SAML SSO and no other method, go to your SAML SSO settings and update the Login method to Only SAML SSO. Once this happens, workspace users will be logged out and required to log back in using SAML SSO. SAML SSO will only be enforced for members who use your verified domain.
On the Business Plan, this will look like this:

On the Enterprise Plan, this will look like this:

SSO bypass
In the event of IdP or SAML failure, certain users will be able to bypass SAML SSO by using their email and password credentials. They’ll be able to log in and disable or update their configuration.
If a SAML configuration is managed at the organization level, only organization owners will be able to bypass SSO.
If a SAML configuration is managed at the workspace level, only workspace owners will be able to bypass SSO.
참고: 이 기능은 엔터프라이즈 요금제 사용자만 사용할 수 있습니다. 이 기능을 활성화하기 위해 도메인 인증이 필요한 것은 아닙니다.
Workspace-level SAML authorization allows enterprises to require SAML SSO for workspace access, regardless of a user's email domain. This enables safer external collaboration in your workspace.
To enable workspace-level SAML authorization:
Open the workspace switcher and select
Manage organization. You may need toSet up organizationfirst if you haven’t already. Learn more here →In the
Generaltab of your organization settings, toggle onRequire SAML authorization for workspace access.
참고: 활성화하기 전에 모든 멤버가 ID 공급자(IdP)에 추가되어 있는지 확인하여 멤버의 워크스페이스 이용이 차단되는 문제를 방지하세요.
When enabled, members of the affected workspaces who haven’t already authorized with your organization’s IdP will be met with an additional authorization screen. They’ll need to go through SAML SSO to continue viewing your organization’s workspaces.

Notion supports Just-in-Time provisioning when using SAML SSO. This allows someone signing in via SAML SSO to join the workspace automatically as a member. You can turn this on while you set up SAML, in the same save.
To enable Just-in-Time provisioning if you're on the Business Plan, go to Settings → Identity and make sure that Automatic account creation is enabled.
To enable Just-in-Time provisioning if you’re on the Enterprise Plan, go to your organization settings → General and make sure that Automatic account creation is enabled.
참고: SCIM을 사용하는 경우 JIT 프로비저닝을 권장하지 않습니다.'허용된 이메일 도메인'이 있으면 해당 도메인의 사용자가 워크스페이스에 참여할 수 있으므로 ID 공급자와 Notion의 멤버가 일치하지 않을 수 있습니다.
더 알아보기
자주 묻는 질문(FAQ)
SAML SSO(통합로그인)를 활성화할 수 없는 이유는 무엇인가요?
SAML SSO(통합로그인)를 활성화할 수 없는 이유는 무엇인가요?
가장 일반적인 이유는 아직 도메인 소유권을 인증받지 않았기 때문입니다. 이 경우 인증된 이메일 도메인 섹션에 표시된 도메인이 없거나, 도메인이 인증 대기 중으로 나타납니다.
다음 단계를 진행하기 전에 도메인 인증을 완료하는 방법을 알아보세요 →
SAML SSO(통합로그인) 설정을 변경할 수 없는 이유는 무엇인가요?
SAML SSO(통합로그인) 설정을 변경할 수 없는 이유는 무엇인가요?
이미 다른 SSO 구성에 연결된 워크스페이스에서 인증된 도메인이나 SSO 구성을 수정하려고 시도한 것일 수 있습니다.
연결된 워크스페이스에서는 모든 도메인 관리와 SSO 구성 설정이 읽기 전용입니다. SSO 구성을 변경하거나 해당 워크스페이스를 SSO 구성에서 제거하려면 기본 워크스페이스의 사용 권한이 필요합니다. 기본 워크스페이스의 이름은 설정 내 신원 & 프로비저닝탭 상단에 표시되어 있습니다.
SSO를 활성화하기 위해 도메인을 인증해야 하는 이유는 무엇인가요?
SSO를 활성화하기 위해 도메인을 인증해야 하는 이유는 무엇인가요?
도메인 소유자만 사용자의 Notion 로그인 방법을 변경할 수 있도록 하기 위해 이메일 도메인 소유권을 인증받게 하는 것입니다.
SSO를 설정하는 데 문제가 발생했습니다.
SSO를 설정하는 데 문제가 발생했습니다.
XML 대신 URL을 사용해 보세요.
사용자에게 적용하기 전 테스트 계정으로 설정 절차를 점검해 보세요.
위의 방법으로 문제가 해결되지 않으면
team@makenotion.com으로 지원을 요청하세요.
워크스페이스의 SAML SSO를 구성하기 전에 "허용된 이메일 도메인" 설정에서 이메일 도메인을 제거해야 하는 이유는 무엇인가요?
워크스페이스의 SAML SSO를 구성하기 전에 "허용된 이메일 도메인" 설정에서 이메일 도메인을 제거해야 하는 이유는 무엇인가요?
허용된 이메일 도메인을 설정하면 선택한 도메인을 소유한 사용자가 ID 공급자를 통해 프로비저닝되지 않은 상태로 워크스페이스에 접근할 수 있게 됩니다. SAML을 활성화한 워크스페이스에 ID 공급자를 통해 프로비저닝된 사용자만 접근할 수 있게 제한하려면 허용된 이메일 도메인 목록에서 모든 이메일 주소를 제거하여 이 기능을 비활성화하세요.
제가 사용하는 ID 공급자가 영업을 중단한 경우에도 Notion에 로그인할 수 있나요?
제가 사용하는 ID 공급자가 영업을 중단한 경우에도 Notion에 로그인할 수 있나요?
네. SAML이 적용되더라도 워크스페이스 소유자는 이메일로 로그인할 수 있습니다. 워크스페이스 소유자는 SAML 적용을 비활성화하도록 SAML 구성을 변경하여 사용자가 다시 이메일로 로그인할 수 있도록 허용할 수 있습니다.
SAML 구성에 연결된 다른 워크스페이스의 관리자가 새로운 워크스페이스를 생성하도록 허용하려면 어떻게 해야 하나요?
SAML 구성에 연결된 다른 워크스페이스의 관리자가 새로운 워크스페이스를 생성하도록 허용하려면 어떻게 해야 하나요?
기본 워크스페이스의 관리자만 인증된 도메인을 사용하여 새로운 워크스페이스를 만들 수 있습니다. 기본 SAML 워크스페이스를 SAML 구성에 연결된 다른 워크스페이스로 전환하려면 team@makenotion.com으로 Notion 지원팀에 문의해 주세요.
Do I have to save my SAML settings twice?
Do I have to save my SAML settings twice?
No. You can add your provider details, pick how people sign in, and choose whether new accounts are created, then save once. Everything takes effect together.
