Skip to main content

Configure SSO and Directory Sync

Blast Audit groups identity setup under `Identity integrations` in the dashboard. From there, owners and admins can launch WorkOS for both `Single Sign-On` and `Directory sync`.

Written by William Karkegi
Updated over 2 weeks ago

Blast Audit groups identity setup under Identity integrations in the dashboard. From there, owners and admins can launch WorkOS for both Single Sign-On and Directory sync.

Who this is for

  • Organization owners and admins

  • IT teams configuring SSO and SCIM with WorkOS

  • Anyone responsible for secure access and seat provisioning

Before you begin

  • You need dashboard admin access and the correct organization selected

  • You need control over your corporate domain or access to the person who manages DNS

  • The dashboard requires a verified organization domain before SSO or SCIM can be configured

  • Decide first whether you need only SSO, or SSO plus directory provisioning

How to do it

  1. Open the dashboard and go to Identity integrations.

  2. If you see the domain gate, click Verify domain in WorkOS.

  3. Add the DNS TXT record requested by WorkOS, then return after verification succeeds.

  4. Open Single Sign-On and click Add connection.

  5. In WorkOS, complete the SSO setup for your identity provider. The in-app checklist expects you to exchange SAML metadata, verify ACS URLs, and test login for both admin and member roles.

  6. Return to Blast Audit and review Connection health. Check the status badge, Primary connection, and Total connections.

  7. Open Directory Sync and click Connect provider when you are ready to configure SCIM.

  8. In WorkOS, generate the SCIM credentials and complete the provider-side connection.

  9. Return to the dashboard and review Sync status, Last sync, Primary directory, and Total directories.

  10. Back on Identity integrations, review the Audit log for recent WorkOS events.

Expected result

  • Your domain is verified before you try to add SSO or SCIM

  • Single Sign-On no longer sits in an unconfigured state

  • Admin and member logins are both tested, not just the owner path

  • Directory Sync is connected intentionally and its status is understood by the IT owner

  • The Audit log shows the events you expect after configuration

Avoid this

  • Trying to add SSO before domain verification

  • Testing only one role and assuming the full setup is safe

  • Expecting directory provisioning to be instant without checking the provider-side setup first

  • Launching the wrong organization from WorkOS because the dashboard session was on the wrong workspace

If it still doesn't work

  • If the dashboard says Select an organization before continuing., fix organization context first

  • If WorkOS does not open, retry and note the exact message, such as Unable to open the WorkOS Admin Portal.

  • If the domain gate keeps appearing, verify that the DNS TXT record is published and recognized by WorkOS

  • If you need non-admin users to access the dashboard itself, handle role and membership first, then return to identity setup

Read next

  • Complete Dashboard Onboarding

  • Invite Members and Assign Roles

  • Contact Support with Intercom

  • Use Dashboard Exports

Did this answer your question?