SAML SSO
Notion provides Single Sign-On (SSO) functionality for Business and Enterprise customers to access the app through a single authentication source. This allows IT administrators to better manage team access and keeps information more secure.
ข้ามไปยังคำถามที่พบบ่อยหมายเหตุ: ฟีเจอร์นี้ใช้งานได้เฉพาะสำหรับผู้ใช้ในแพ็คเกจ Business หรือ Enterprise เท่านั้น
With SSO, you can streamline user management across systems, and remove the need for end-users to remember and manage multiple passwords by allowing them to sign in at one single access point and enjoy a seamless experience across multiple applications.
To use SSO with Notion:
Your workspace must be on a Business Plan or Enterprise Plan.
Your Identity Provider (IdP) must support the SAML 2.0 standard. See instructions for Identity Provider setup for specific apps here →
A workspace owner must configure SAML SSO for the Notion workspace.
At least one domain must be verified by a workspace owner. Learn more about domain verification →
หมายเหตุ: เฉพาะสมาชิกพื้นที่ทำงานเท่านั้นที่สามารถใช้ SAML SSO เพื่อเข้าสู่ระบบได้ ผู้ใช้ชั่วคราวที่ได้รับเชิญให้เข้าถึงหน้าในพื้นที่ทำงาน Notion ที่เปิดใช้งาน SAML จะไม่สามารถเข้าสู่ระบบด้วย SAML SSO ได้ แต่จะต้องใช้วิธีเข้าสู่ระบบอื่นแทน เช่น ชื่อผู้ใช้และรหัสผ่าน หรือเข้าสู่ระบบด้วย Google หรือ Apple
Business Plan
To set up SAML SSO for a Business workspace, a workspace owner can:
Go to
Settings→General.In the
Allowed email domainssection, remove all email domains.Select the
Identitytab inSettings.
Verify one or more domains. See instructions for domain verification here →
Toggle on
Enable SAML SSOand the SAML SSO Configuration modal will automatically appear and prompt you to complete the set-up.The SAML SSO Configuration modal is divided into two parts:
The
Assertion Consumer Service (ACS) URLneeds to be entered in your Identity Provider (IdP) portal.The
Identity Provider Detailsis a field in which you need to provide either an IdP URL or IdP metadata XML.
Choose how people sign in and whether new accounts are created for them, then select
Save & enable. You can make all of these choices before you save. You don’t need to save first and open the settings again.

Enterprise Plan
Enterprise Plan organization owners can manage SAML SSO for their workspace (or multiple workspaces belonging to their organization) by following these steps:
Open the workspace switcher and select Manage organization. You may need to Set up organization first if you haven’t already. Learn more here →
In the
Generaltab of your organization settings, toggle onEnable SAML SSO.Choose a setup method (URL or metadata XML), paste the required information from your Identity Provider or IdP, and select
Save & enable. You can also pick how people sign in and turn on automatic account creation before you save, so everything takes effect at once.
หมายเหตุ: ในขณะนี้ องค์กรที่ใช้แพ็คเกจ Enterprise สามารถตั้งค่า SAML SSO ได้กับ IdP เพียงหนึ่งรายการเท่านั้น
Once you have completed your configuration of SAML SSO for a workspace, members will be able to log in via SAML SSO in addition to other login methods, like username and password or Google authentication.
You can pick this while you are first setting up SAML, in the same save. You can also change it later.
If you want to ensure that members can log in using only SAML SSO and no other method, go to your SAML SSO settings and update the Login method to Only SAML SSO. Once this happens, workspace users will be logged out and required to log back in using SAML SSO. SAML SSO will only be enforced for members who use your verified domain.
On the Business Plan, this will look like this:

On the Enterprise Plan, this will look like this:

SSO bypass
In the event of IdP or SAML failure, certain users will be able to bypass SAML SSO by using their email and password credentials. They’ll be able to log in and disable or update their configuration.
If a SAML configuration is managed at the organization level, only organization owners will be able to bypass SSO.
If a SAML configuration is managed at the workspace level, only workspace owners will be able to bypass SSO.
หมายเหตุ: ฟีเจอร์นี้มีให้ใช้งานเฉพาะผู้ใช้ในแพ็คเกจ Enterprise เท่านั้น ไม่จำเป็นต้องมีการยืนยันโดเมนเพื่อเปิดใช้งานฟีเจอร์นี้
Workspace-level SAML authorization allows enterprises to require SAML SSO for workspace access, regardless of a user's email domain. This enables safer external collaboration in your workspace.
To enable workspace-level SAML authorization:
Open the workspace switcher and select
Manage organization. You may need toSet up organizationfirst if you haven’t already. Learn more here →In the
Generaltab of your organization settings, toggle onRequire SAML authorization for workspace access.
หมายเหตุ: ก่อนเปิดใช้งาน โปรดตรวจสอบให้แน่ใจว่าได้เพิ่มสมาชิกทุกคนไปยัง Identity Provider (IdP) ของคุณแล้ว เพื่อป้องกันไม่ให้สมาชิกถูกล็อกออกจากพื้นที่ทำงานโดยไม่ตั้งใจ
When enabled, members of the affected workspaces who haven’t already authorized with your organization’s IdP will be met with an additional authorization screen. They’ll need to go through SAML SSO to continue viewing your organization’s workspaces.

Notion supports Just-in-Time provisioning when using SAML SSO. This allows someone signing in via SAML SSO to join the workspace automatically as a member. You can turn this on while you set up SAML, in the same save.
To enable Just-in-Time provisioning if you're on the Business Plan, go to Settings → Identity and make sure that Automatic account creation is enabled.
To enable Just-in-Time provisioning if you’re on the Enterprise Plan, go to your organization settings → General and make sure that Automatic account creation is enabled.
หมายเหตุ: เราไม่แนะนำให้เปิดใช้งานการจัดเตรียมแบบ Just-in Time หากคุณกำลังใช้ SCIM การมี “โดเมนอีเมลที่อนุญาต” จะช่วยให้ผู้ใช้ในโดเมนนั้นสามารถเข้าร่วมพื้นที่ทำงานได้ ดังนั้นจึงอาจเกิดความไม่ตรงกันระหว่างการเป็นสมาชิกใน Identity Provider ของพวกเขากับ Notion
ดูข้อมูลเพิ่มเติม
คำถามที่พบบ่อย
ทำไมฉันถึงเปิดใช้งาน SAML SSO ไม่ได้
ทำไมฉันถึงเปิดใช้งาน SAML SSO ไม่ได้
เหตุผลที่พบบ่อยที่สุดคือคุณยังไม่ได้ยืนยันความเป็นเจ้าของโดเมน หากเป็นกรณีนี้ คุณจะสังเกตเห็นว่าคุณไม่มีโดเมนใดแสดงอยู่ในส่วนการยืนยันโดเมนอีเมล หรือโดเมนนั้นกำลังรอการยืนยันอยู่
สำหรับขั้นตอนถัดไป โปรดดูคำแนะนำของเราเกี่ยวกับวิธีการยืนยันโดเมนให้เสร็จสมบูรณ์ที่นี่ →
ทำไมฉันถึงแก้ไขการตั้งค่า SAML SSO ของฉันไม่ได้
ทำไมฉันถึงแก้ไขการตั้งค่า SAML SSO ของฉันไม่ได้
เป็นไปได้ว่าคุณกำลังพยายามแก้ไขโดเมนที่ยืนยันแล้วหรือการกำหนดค่า SSO จากพื้นที่ทำงานที่เชื่อมโยง ซึ่งได้เชื่อมโยงกับการกำหนดค่า SSO อื่นอยู่แล้ว
ในพื้นที่ทำงานที่เชื่อมโยง การจัดการโดเมนและการตั้งค่า SSO จะอยู่ในโหมดอ่านอย่างเดียว หากต้องการแก้ไขการตั้งค่า SSO หรือเอาพื้นที่ทำงานนี้ออกจากการตั้งค่า SSO คุณต้องเข้าถึงพื้นที่ทำงานหลัก คุณสามารถดูชื่อพื้นที่ทำงานหลักได้ที่ด้านบนของแท็บ Identity & Provisioning ในการตั้งค่าของคุณ
ทำไมฉันจึงต้องยืนยันโดเมนเพื่อเปิดใช้งาน SSO
ทำไมฉันจึงต้องยืนยันโดเมนเพื่อเปิดใช้งาน SSO
เราขอให้ตรวจสอบความเป็นเจ้าของโดเมนอีเมล เพื่อให้แน่ใจว่าเฉพาะเจ้าของโดเมนอีเมลเท่านั้นที่สามารถปรับแต่งวิธีที่ผู้ใช้เข้าสู่ระบบ Notion ได้
ฉันกำลังประสบปัญหาในการตั้งค่า SSO
ฉันกำลังประสบปัญหาในการตั้งค่า SSO
ลองใช้ URL แทน XML
ทดสอบกระบวนการตั้งค่าด้วยบัญชีทดสอบก่อนที่จะบังคับใช้กับผู้ใช้
หากตัวเลือกเหล่านี้ไม่สามารถช่วยได้ โปรดติดต่อฝ่ายสนับสนุนที่
ทำไมฉันถึงควรลบโดเมนอีเมลออกจากการตั้งค่า “โดเมนอีเมลที่อนุญาต” ก่อนที่จะกำหนดค่า SAML SSO สำหรับพื้นที่ทำงานของฉัน
ทำไมฉันถึงควรลบโดเมนอีเมลออกจากการตั้งค่า “โดเมนอีเมลที่อนุญาต” ก่อนที่จะกำหนดค่า SAML SSO สำหรับพื้นที่ทำงานของฉัน
การตั้งค่า โดเมนอีเมลที่อนุญาต ช่วยให้ผู้ใช้ในโดเมนที่เลือกสามารถเข้าถึงพื้นที่ทำงานของคุณได้โดยไม่ต้องผ่านการจัดเตรียมผ่าน IdP เพื่อให้แน่ใจว่าเฉพาะผู้ใช้ที่ได้รับการจัดเตรียมผ่าน IdP เท่านั้นที่จะสามารถเข้าถึงพื้นที่ทำงานที่เปิดใช้งาน SAML ได้ ให้ปิดฟีเจอร์นี้โดยนำที่อยู่อีเมลทั้งหมดออกจากลิสต์ โดเมนอีเมลที่อนุญาต
ฉันยังสามารถลงชื่อเข้าใช้ Notion ได้หรือไม่หากผู้ให้บริการข้อมูลประจำตัว (IdP) ของฉันไม่สามารถใช้งานได้?
ฉันยังสามารถลงชื่อเข้าใช้ Notion ได้หรือไม่หากผู้ให้บริการข้อมูลประจำตัว (IdP) ของฉันไม่สามารถใช้งานได้?
ได้ แม้ว่าจะมีการบังคับใช้ SAML เจ้าของพื้นที่ทำงานก็ยังมีตัวเลือกในการลงชื่อเข้าใช้ด้วยอีเมล เจ้าของพื้นที่ทำงานสามารถเปลี่ยนการกำหนดค่า SAML เพื่อปิดใช้งาน บังคับใช้ SAML เพื่อให้ผู้ใช้สามารถลงชื่อเข้าใช้ด้วยอีเมลได้อีกครั้ง
ฉันจะอนุญาตให้ผู้ดูแลของพื้นที่ทำงานอื่นในกำหนดค่า SAML ของฉันสร้างพื้นที่ทำงานใหม่ได้อย่างไร
ฉันจะอนุญาตให้ผู้ดูแลของพื้นที่ทำงานอื่นในกำหนดค่า SAML ของฉันสร้างพื้นที่ทำงานใหม่ได้อย่างไร
เฉพาะผู้ดูแลของพื้นที่ทำงานหลักของคุณเท่านั้นที่จะสามารถสร้างพื้นที่ทำงานใหม่โดยใช้โดเมนที่ยืนยันแล้วของคุณได้ โปรดติดต่อทีมสนับสนุนของเรา (team@makenotion.com) เพื่อเปลี่ยนพื้นที่ทำงาน SAML หลักของคุณไปยังพื้นที่ทำงานที่เชื่อมโยงอื่นในกำหนดค่า SAML ของคุณ
Do I have to save my SAML settings twice?
Do I have to save my SAML settings twice?
No. You can add your provider details, pick how people sign in, and choose whether new accounts are created, then save once. Everything takes effect together.
