{"meta":{"title":"Using SAML for enterprise IAM","intro":"You can centrally manage accounts and access to your GitHub Enterprise Server instance with SAML single sign-on (SSO).","product":"Enterprise administrators","breadcrumbs":[{"href":"/en/enterprise-server@3.22/admin","title":"Enterprise administrators"},{"href":"/en/enterprise-server@3.22/admin/managing-iam","title":"Identity and access management"},{"href":"/en/enterprise-server@3.22/admin/managing-iam/using-saml-for-enterprise-iam","title":"SAML for enterprise IAM"}],"documentType":"subcategory"},"body":"# Using SAML for enterprise IAM\n\nYou can centrally manage access to  with SAML single sign-on (SSO).\n\n## Links\n\n* [/deciding-whether-to-configure-saml-for-your-enterprise-or-your-organizations](/en/enterprise-server@3.22/deciding-whether-to-configure-saml-for-your-enterprise-or-your-organizations)\n\n* [Configuring SAML single sign-on for your enterprise](/en/enterprise-server@3.22/admin/managing-iam/using-saml-for-enterprise-iam/configuring-saml-single-sign-on-for-your-enterprise)\n\n  You can control and secure access to  by  SAML single sign-on (SSO) through your identity provider (IdP).\n\n* [/managing-team-synchronization-for-organizations-in-your-enterprise](/en/enterprise-server@3.22/managing-team-synchronization-for-organizations-in-your-enterprise)\n\n* [/configuring-saml-single-sign-on-for-your-enterprise-using-okta](/en/enterprise-server@3.22/configuring-saml-single-sign-on-for-your-enterprise-using-okta)\n\n* [/disabling-saml-single-sign-on-for-your-enterprise](/en/enterprise-server@3.22/disabling-saml-single-sign-on-for-your-enterprise)\n\n* [Enabling encrypted assertions](/en/enterprise-server@3.22/admin/managing-iam/using-saml-for-enterprise-iam/enabling-encrypted-assertions)\n\n  You can improve GitHub.com's security with SAML single sign-on (SSO) by encrypting the messages that your SAML identity provider (IdP) sends.\n\n* [Updating a user's SAML NameID](/en/enterprise-server@3.22/admin/managing-iam/using-saml-for-enterprise-iam/updating-a-users-saml-nameid)\n\n  When an account's NameID changes on your identity provider (IdP) and the person can no longer sign into GitHub.com, you must update the NameID mapping on GitHub.com.\n\n* [/switching-your-saml-configuration-from-an-organization-to-an-enterprise-account](/en/enterprise-server@3.22/switching-your-saml-configuration-from-an-organization-to-an-enterprise-account)\n\n* [Troubleshooting SAML authentication](/en/enterprise-server@3.22/admin/managing-iam/using-saml-for-enterprise-iam/troubleshooting-saml-authentication)\n\n  If you use SAML single sign-on (SSO) and people are unable to authenticate to access GitHub, you can troubleshoot the problem."}