{"meta":{"title":"Using SAML for enterprise IAM","intro":"You can centrally manage access to your enterprise's resources with SAML single sign-on (SSO) and System for Cross-domain Identity Management (SCIM).","product":"Enterprise administrators","breadcrumbs":[{"href":"/en/enterprise-cloud@latest/admin","title":"Enterprise administrators"},{"href":"/en/enterprise-cloud@latest/admin/managing-iam","title":"Identity and access management"},{"href":"/en/enterprise-cloud@latest/admin/managing-iam/using-saml-for-enterprise-iam","title":"SAML for enterprise IAM"}],"documentType":"subcategory"},"body":"# Using SAML for enterprise IAM\n\nYou can centrally manage access to  with SAML single sign-on (SSO).\n\n## Links\n\n* [Deciding whether to configure SAML for your enterprise or your organizations](/en/enterprise-cloud@latest/admin/managing-iam/using-saml-for-enterprise-iam/deciding-whether-to-configure-saml-for-your-enterprise-or-your-organizations)\n\n  You can configure SAML for your enterprise account, with the same configuration applying to all of its organizations, or you can create separate configurations for individual organizations.\n\n* [Configuring SAML single sign-on for your enterprise](/en/enterprise-cloud@latest/admin/managing-iam/using-saml-for-enterprise-iam/configuring-saml-single-sign-on-for-your-enterprise)\n\n  You can control and secure access to  by  SAML single sign-on (SSO) through your identity provider (IdP).\n\n* [Managing team synchronization for organizations in your enterprise](/en/enterprise-cloud@latest/admin/managing-iam/using-saml-for-enterprise-iam/managing-team-synchronization-for-organizations-in-your-enterprise)\n\n  You can enable team synchronization between Microsoft Entra ID (previously known as Azure AD) and GitHub to allow organizations owned by your enterprise account to manage team membership through IdP groups.\n\n* [Configuring SAML single sign-on for your enterprise using Okta](/en/enterprise-cloud@latest/admin/managing-iam/using-saml-for-enterprise-iam/configuring-saml-single-sign-on-for-your-enterprise-using-okta)\n\n  You can use Security Assertion Markup Language (SAML) single sign-on (SSO) with Okta to automatically manage access to your enterprise account on GitHub.\n\n* [Disabling SAML single sign-on for your enterprise](/en/enterprise-cloud@latest/admin/managing-iam/using-saml-for-enterprise-iam/disabling-saml-single-sign-on-for-your-enterprise)\n\n  You can disable SAML single sign-on (SSO) for your enterprise account.\n\n* [/enabling-encrypted-assertions](/en/enterprise-cloud@latest/enabling-encrypted-assertions)\n\n* [/updating-a-users-saml-nameid](/en/enterprise-cloud@latest/updating-a-users-saml-nameid)\n\n* [Switching your SAML configuration from an organization to an enterprise account](/en/enterprise-cloud@latest/admin/managing-iam/using-saml-for-enterprise-iam/switching-your-saml-configuration-from-an-organization-to-an-enterprise-account)\n\n  Learn special considerations and best practices for replacing an organization-level SAML configuration with an enterprise-level SAML configuration.\n\n* [Troubleshooting SAML authentication](/en/enterprise-cloud@latest/admin/managing-iam/using-saml-for-enterprise-iam/troubleshooting-saml-authentication)\n\n  If you use SAML single sign-on (SSO) and people are unable to authenticate to access GitHub, you can troubleshoot the problem."}