Set up Single Sign-On (SSO) and Just-in-Time (JIT) login and signup settings
Control how individuals access your SSO-managed teams. This setting will affect anyone who signs up or logs in with an email associated with your domains.
Additionally, you can enable the JIT setting to ensure that people logging in and signing up via SSO are automatically added to your team.
SSO login is available to Canva Enterprise, Canva Education, and Canva for Campus. Meanwhile, JIT provisioning is only available to Canva Enterprise and Canva for Campus. Only team administrators and owners can enable, configure, and change their team or district’s SSO and JIT settings.
SSO and JIT provisioning are different from and are not affected by the Team Access settings found in the Permissions tab.
Step 1: Accessing SSO and JIT settings
- From the homepage, select your Profile icon.
- Select Settings.
- From the side menu, scroll down, then select SSO and provisioning tab.
Step 2: Choosing SSO signup and login controls
- Under Configure your settings dropdown, select from the options below.
SSO optional for everyone
Everyone with a verified email from your domain can still choose other ways of logging in to Canva.
SSO required for everyone on your team
What this means for different types of users.
- New Canva users will be required to sign up using SSO and will be added to the team.
- Existing Canva users who are part of the team will be required to link their account to the SSO provider, then log in again via SSO.
- Existing Canva users who are not part of the team can log in to Canva using SSO or other methods.
SSO required for everyone (even outside of your team)
What this means for different types of users.
- New Canva users will be required to sign up using SSO and will be added to the team.
- Existing Canva users who are part of the team will be required to link their account to the SSO provider, then log in again via SSO.
- Existing Canva users who are not part of the team will be required to link their account to the SSO provider or change their email.
Before making SSO required for your team, make sure that users with Canva accounts linked to your email domain switch to a personal email address to avoid getting locked out.
If users on your domain (both on your team and outside of your team) are unable to access Canva after enabling SSO, here’s how to help them regain access.
For current/existing team members
- Make sure to provide them access to the Canva SAML app through your SSO identity provider.
For non-team members
- Update your SSO settings in Canva to SSO required for everyone on your team instead of SSO required for everyone.
- Request to change their email to a personal email address so they’re not using your organisation’s domain.
To force log out all existing users with verified domain emails, refer to the Force logout SSO logins section in the Setting up Single Sign-On (SSO) for Teams article.
Step 3: Choosing JIT provisioning
The JIT feature is automatically activated in your Settings. When Just In Time (JIT) Provisioning is activated:
- user account creation is automated the first time users log in using Single Sign-On (SSO)
- user information is updated whenever changes happen in your Identity Provider (IdP)
- users logging in through SSO are automatically added to your team
Charges for members exceeding your contracted seat count will reflect in your next billing cycle.
How to disable JIT provisioning
- Follow steps 1-2 above.
- Below the SSO settings, untick the Allow users to sign up via SSO with Just-In-Time (JIT) provisioning checkbox.
When JIT is disabled, users that are not part of your team will be unable to use SSO, and user details for existing users will no longer receive updates. The only way to provision team members will be with SCIM. Learn more about SCIM user provisioning and de-provisioning.
If your team does not have an alternative method for user provisioning, but you want to require SSO for your team, keep your JIT provisioning enabled.
How to enable JIT provisioning
To enable your JIT Provisioning, tick the Allow users to sign up via SSO with Just-In-Time (JIT) provisioning checkbox below the SSO settings.
Tip: If you want to keep the JIT provisioning enabled while controlling team additions, configure your Canva SAML app to grant access only to users you wish to join your Canva team and disable it for everyone else on your identity provider.
Once you update your Canva SAML app, please make sure that your SSO signup and login controls is set to SSO required for everyone on your team. This will allow users who are not assigned to your Canva SAML app and not members of your Canva team to log in without SSO.
Was this helpful?
Helpful
Unhelpful