Skip to content
English
  • There are no suggestions because the search field is empty.

Configure Single Sign-On (SSO) and Auto-Provisioning

SSO lets your organization's users sign in to Skyllful with your identity provider, and this article shows Local Administrators how auto-provisioning grants access and assigns a manager, role, and tags from SSO claims.

What are SSO and auto-provisioning in Skyllful?

  • SSO (single sign-on) lets your users sign in to Skyllful with your identity provider, such as Microsoft Entra ID or Okta.
  • Skyllful supports both OpenID Connect and SAML identity providers.
  • Auto-provisioning creates a user's Skyllful account the first time they sign in with SSO.
  • Auto-provisioning also assigns a manager, a role, and tags automatically, based on the values in the SSO claims.

Who sets up SSO?

The connection to your identity provider (OpenID Connect or SAML) is set up with Skyllful. Once SSO is connected, Local Administrators manage auto-provisioning in Learning Program Settings. Confirm the exact split of responsibilities with your Skyllful representative.


Where do you manage auto-provisioning?

Step Action
1 Open the Learning Program in Skyllful Studio.
2 Open Learning Program Settings (the gear icon).
3 Open the SSO Management tab.
4 Turn on the Enabled toggle for Auto-Provisioning Settings.

The SSO Management tab, with Auto-Provisioning Settings and claim mappings.


How do claim mappings work?

Default Assigned Manager

  • Map a Claim and Claim Value to a Manager.
  • Select the plus to add a mapping.

Default Assigned Role

  • Map a Claim and Claim Value to a Role, for example Employee.
  • Select the plus to add a mapping.

Tags to Add to User

  • Map a Claim and Claim Value to one or more Tags.
  • Use Select Multiple to choose the Tags.

How is a user set up at first sign-in?

Each mapping has a Default row that applies when no claim value matches.

If Then
The SSO claim value matches a mapping you created The user is assigned the manager, role, or tags for that value.
The SSO claim value does not match any mapping The user is assigned the values in the Default row.
Auto-provisioning is turned off The user is not created automatically; add the user in User Management.

Frequently asked questions

What happens if a user's claim does not match any mapping?

The user is assigned the Default manager, role, and tags.

Can you change a user's role after auto-provisioning?

Yes. You can edit the user later in User Management.


Related Articles

  • [LINK TO: User Management Overview] — How to manage users in a Learning Program.
  • [LINK TO: Add a User] — How to add a user manually.
  • [LINK TO: User Permissions] — How roles and permissions work.

Last Reviewed: August 8, 2026 | Skyllful Knowledge Base | Local Administrators