Skip to content

Single sign-on (SSO) authenticates ALTR administrators through your organization’s identity provider (IdP) instead of a separate ALTR password. System for Cross-domain Identity Management (SCIM) provisions and deprovisions ALTR administrator accounts directly from that IdP. The two work together but control different things: SSO controls how an administrator signs in, and SCIM controls whether their ALTR account exists at all. Super Administrators configure both from the SSO/SCIM tab under Settings > Preferences.

When SSO is enabled for your organization, administrators no longer have ALTR passwords. Authentication is handled entirely by the IdP.

ALTR matches users between the IdP and ALTR by username: an administrator’s ALTR username must match their IdP username exactly, including case. A mismatch causes authentication to fail. Changing an ALTR username requires contacting ALTR Support.

When SSO is enabled, two-factor authentication prompts are also deferred to the IdP rather than handled by ALTR.

System for Cross-domain Identity Management (SCIM)

Section titled “System for Cross-domain Identity Management (SCIM)”

When SCIM is enabled, your IdP becomes the source of truth for administrator accounts: user creation, role assignment, and deactivation all happen through the IdP, and ALTR’s user-management API endpoints are blocked.

The Data Consumer role can only be assigned through SCIM provisioning. It isn’t available through the ALTR UI. SCIM is currently supported for Okta only; Microsoft Entra ID is SSO-only, so the Data Consumer role isn’t available through Entra ID. See Administrators for what each role can do.

If SSO is enabled but SCIM isn’t, administrators must be manually created in ALTR before they can authenticate through your IdP: SSO only authenticates existing accounts, it doesn’t create them.

Turning off SSO or SCIM can’t be done from the ALTR UI. Submit a Change Request to ALTR Support. Disabling SSO also requires each affected administrator to go through the password-reset flow to set an ALTR password again.