---
title: Linq SSO Integration
description: "Linq SSO via SAML (Entra/Azure AD): set domains, paste IdP metadata (EntityID/SSO URL/cert), test sign-in, enforce SSO"
---

[Skip to content](https://help.linqapp.com/linq-sso-integration#main-content)

English

Show submenu for translations

[![Cube-Linq-w](https://help.linqapp.com/hs-fs/hubfs/Cube-Linq-w.png?width=200&height=89&name=Cube-Linq-w.png)](https://linqapp.com/?hsLang=en)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [Go to linqapp.com](https://linqapp.com/)

[Go to linqapp.com](https://linqapp.com/?hsLang=en)

 How can we help?

- There are no suggestions because the search field is empty.

1. [Help Center](https://help.linqapp.com/?hsLang=en)
2. [Linq One](https://help.linqapp.com/linq-one?hsLang=en)
3. [Admin Dashboard](https://help.linqapp.com/linq-one?hsLang=en#admin-dashboard)

January 16, 2026

# Linq SSO Integration

### 🔐 **Linq SSO Integration (Azure AD / Entra ID)**

### **Overview**

Linq supports **Single Sign-On (SSO)** using through SAML authentication.  
This allows your team to log into Linq securely with their company credentials — no passwords or manual invites required.

### **Available Providers**

| Provider | Notes |
| --- | --- |
| **Okta SAML** | Most commonly used enterprise IdP |
| **Entra ID (Azure AD) SAML** | Microsoft’s cloud identity service |
| **Google SAML** | Works for Google Workspace orgs |
| **ADP OpenID Connect** | Ideal for ADP Workforce or ADP TotalSource users |
| **Auth0 SAML** | Used by teams already managing auth via Auth0 |
| **CAS SAML** | Supports schools and higher-education directories |
| **ClassLink SAML** | Common in education and nonprofit orgs |
| **Cloudflare SAML** | For orgs leveraging Cloudflare Access for identity |
| **CyberArk SAML** | Used in high-security enterprise environments |
| **Duo SAML** | Multi-factor authentication and identity provider |
| **Custom SAML** | Manual setup for unsupported IdPs |
| **Custom OIDC (OpenID Connect)** | For any OIDC-compliant provider (e.g., PingOne, OneLogin) |

---

### **How It Works**

Once connected, employees from your approved company domains can log in to Linq using your organization’s Microsoft credentials.  
Linq verifies their identity through your Azure AD tenant and grants access to the correct organization.

---

### **Setup Steps**

#### **1. Go to Integrations → SSO**

1. Sign in as an **Organization Admin**.
2. Navigate to **Integrations → SSO**.
3. Click **Manage SSO Configuration Settings**.

---

#### **2. Connect Microsoft Entra ID (Azure AD)**

Your admin panel will display:

| Field | Example |
| --- | --- |
| **Identity Provider** | Entra ID (Azure AD) SAML |
| **Domains** | libertyenergy.com, libertyfrac.com, proppx.com, st9go.com |
| **External Domains** | Not allowed |
| **IdP URI (Entity ID)** |   |
| **IdP SSO URL** |   |
| **X.509 Certificate** | Valid (auto-renew via Azure) |

After entering your Azure metadata, click **Test sign-in**.  
When successful, Linq displays **Connection Activated**.

---

#### **3. Verify Attribute Mapping**

Linq automatically maps the standard Azure fields:

| Linq Attribute | IdP Field |
| --- | --- |
| **email** |   |
| **firstName** |   |
| **lastName** |   |
| **id** |   |

No additional mapping is required.

---

#### **4. Manage Sign-In Settings**

In **Integrations → SSO**, admins can control login options:

- **Allow non-SSO logins:** ✅ (recommended during transition)
- **Enforce SSO-only:** toggle OFF if you want to allow both methods  
  *(when ON, all users from approved domains must sign in via SSO)*

---

#### **5. View Sign-In Activity**

Recent login sessions appear under **Sessions** with:

| Column | Example |
| --- | --- |
| Email | name@domain.com |
| Name | name |
| State | Successful / Started |
| Timestamp | Oct 21, 2025, 6:55 PM |

---

### **What’s Working Now**

✅ Entra ID connection active  
✅ Domain whitelisting  
✅ Attribute mapping verified  
✅ Session logging and test sign-in  
✅ Optional non-SSO login toggle

---

### **Best Practices**

- Ensure **certificate validity** before expiry (visible in Linq dashboard).
- Keep **domains** restricted to internal addresses only.
- Use **Test Sign-In** after any Azure metadata update.
- Encourage users to sign in via SSO for consistent authentication.

- [Linq Blue](https://help.linqapp.com/linq-blue?hsLang=en#main-content)
  
  
  
  
  
    - [Linq Blue Subscription](https://help.linqapp.com/linq-blue?hsLang=en#linq-blue-subscription)
    - [Linq Zero](https://help.linqapp.com/linq-blue?hsLang=en#linq-zero)
    - [Integration: GHL](https://help.linqapp.com/linq-blue?hsLang=en#integration-ghl)
    - [Integration: Salesforce](https://help.linqapp.com/linq-blue?hsLang=en#integration-salesforce)
    - [Integration: HubSpot](https://help.linqapp.com/linq-blue?hsLang=en#integration-hubspot)
- [Linq One](https://help.linqapp.com/linq-one?hsLang=en#main-content)
  
  
  
  
  
    - [FAQs](https://help.linqapp.com/linq-one?hsLang=en#faqs)
    - [Linq App](https://help.linqapp.com/linq-one?hsLang=en#linq-app)
    - [Admin Dashboard](https://help.linqapp.com/linq-one?hsLang=en#admin-dashboard)
    - [Products](https://help.linqapp.com/linq-one?hsLang=en#products)
    - [Troubleshooting](https://help.linqapp.com/linq-one?hsLang=en#troubleshooting)
- [API](https://help.linqapp.com/api?hsLang=en#main-content)
  
  
  
  
  
    - [Sandbox](https://help.linqapp.com/api?hsLang=en#sandbox)
    - [API Resources](https://help.linqapp.com/api?hsLang=en#api-resources)

[![Cube-Linq-w](https://help.linqapp.com/hs-fs/hubfs/Cube-Linq-w.png?width=197&height=88&name=Cube-Linq-w.png "Cube-Linq-w")](https://linqapp.com/?hsLang=en)

linqapp.com Help Center

Copyright © 2025, Linq