---
title: "Using SSO with LUSID"
slug: "using-sso-with-lusid"
updated: 2025-12-12T12:30:41Z
published: 2025-12-12T12:30:41Z
canonical: "support.lusid.com/using-sso-with-lusid"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://support.lusid.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Using SSO with LUSID

LUSID supports Single Sign-on (SSO) from any SAML 2.0-compatible identity provider.

This means that:

- Users can authenticate to LUSID without specifying new credentials.
- You retain control over authentication standards (MFA, password policies, and so on).
- Users can be managed in existing systems rather than created anew in LUSID.
- Existing groups can be automatically assigned to roles in LUSID to grant permissions.

To do this:

1. [Contact technical support](/v1/docs/how-do-i-use-the-support-centre) in the first instance to set up your domain for SSO and to discuss requirements and options.
2. Choose either:
  - Just-in-time provisioning. A LUSID user account is automatically created on sign in for the first time but note this LUSID user is not automatically deleted so you will need to delete it yourself if the person leaves your organisation.
  - SCIM provisioning. LUSID user accounts are automatically created and deleted but your choice of identity providers is currently restricted to:
    - Okta. [See how to set this up](/v1/docs/provisioning-lusid-using-okta-and-scim).
    - Microsoft Entra ID (previously Azure AD). For more information, follow Microsoft's instructions on [setting up SSO for LUSID](https://learn.microsoft.com/en-us/azure/active-directory/saas-apps/lusid-tutorial) and then [configuring user provisioning for LUSID](https://learn.microsoft.com/en-gb/azure/active-directory/saas-apps/lusid-provisioning-tutorial).
