How to Set Up Single Sign-On for Your Team's AI Tools

Coding Liquids tutorial cover featuring Sagnik Bhattacharya for How to Set Up Single Sign-On for Your Team's AI Tools.
Coding Liquids tutorial cover featuring Sagnik Bhattacharya for How to Set Up Single Sign-On for Your Team's AI Tools.

You need three things: a business AI plan that offers SSO (ChatGPT Business, Claude Team or Perplexity Enterprise Pro), an identity provider you already pay for (Google Workspace or Microsoft Entra ID), and access to your domain's DNS. Verify the domain, create a SAML app, test one account, then require SSO. Budget two to three hours.

Single sign-on (SSO) means staff sign in to the AI tool with their normal work account instead of a separate password. It fixes sign-in, not membership: ChatGPT Business and Claude Team have no SCIM directory sync, so adding and removing seats stays manual. And Microsoft 365 Copilot and Gemini in Workspace need no SSO at all, because they already run on your work identity.

Follow me on Instagram@sagnikteaches

Which AI plans support SSO, and what each leaves out

Before touching any settings, check your plan. SSO is a workspace feature, so individual subscriptions such as ChatGPT Plus or Claude Pro don't offer it. A "Continue with Google" button on those plans is a login each person chooses for themselves, not something an admin controls.

Connect on LinkedInSagnik Bhattacharya
Tool and planSSOAutomatic user sync (SCIM)Notes
ChatGPT Business ($25/user/month monthly, $20 annual, 2-seat minimum)Yes, SAML or OIDCNoInvites and seat removal are manual
ChatGPT Enterprise (custom quote)YesYesGroup sync through your identity provider
Claude Team ($25/seat monthly, $20 annual, 2-seat minimum)Yes, SAMLNo; just-in-time provisioning insteadSupports Okta, Entra ID, Google, OneLogin, JumpCloud, Duo
Claude EnterpriseYesYesRole mapping by group, automatic removal
Perplexity Enterprise Pro ($40/seat/month)YesYesAlso adds admin controls and internal file search
Microsoft 365 Copilot, Copilot ChatNot neededNot neededUses your Microsoft 365 sign-in
Gemini in Google WorkspaceNot neededNot neededUses your Workspace sign-in

If your team is still on shared or personal ChatGPT logins, the plan question comes first; when a shared ChatGPT plan stops being enough covers that decision, and whether Claude Team is worth it does the same for Anthropic's plan.

Subscribe on YouTube@codingliquids

What SSO changes for a nine-person HVAC installer

Consider an illustrative heating and air-conditioning installer with nine staff on Microsoft 365 and ChatGPT Business. Before SSO, each person had a ChatGPT password. Two engineers had joined the workspace with personal Gmail addresses because that is what their phones were signed in with. When a service coordinator left, her Microsoft 365 account was blocked the same afternoon, but she could still sign in to ChatGPT from home for three weeks, because nobody remembered it had its own password. She had a project full of customer addresses and maintenance contract notes.

After SSO, everyone signs in to ChatGPT through Microsoft. Blocking a Microsoft 365 account now blocks ChatGPT sign-in at the same moment. The two Gmail users were moved to work addresses during the switch-over. What SSO didn't change: the leaver's seat still sat on the invoice until the owner removed it in ChatGPT's member settings. At $25 a month on monthly billing, a seat forgotten for a quarter costs $75, which is why SSO belongs alongside a proper staff offboarding checklist, not instead of one.

Stage 1: pick the identity provider you already have (20 minutes)

An identity provider is the system that holds your staff accounts and vouches for them. Most small businesses already have one without calling it that.

  • Google Workspace. A super administrator can add a custom SAML app under Apps, then Web and mobile apps, then Add app, then Add custom SAML app. You then choose which users or groups can use it.
  • Microsoft Entra ID (the directory behind Microsoft 365). The free tier included with Microsoft 365 business plans supports SAML single sign-on to SaaS apps. Look for the AI tool in the Enterprise applications gallery; if it isn't listed, create your own non-gallery application. Conditional Access rules, such as allowing sign-in only from company laptops, need Entra ID P1, which Microsoft 365 Business Premium ($22/user/month annual) includes.
  • Okta, JumpCloud or similar. If you already run one, use it; both ChatGPT Business and Claude Team list them as supported.

Pick one. Running SSO for ChatGPT through Google and for Claude through Microsoft doubles the places a leaver must be removed from.

Stage 2: verify your domain (15 minutes, plus the DNS wait)

Both OpenAI and Anthropic make you prove you own your email domain before SSO can be set up. You do that by adding a TXT record, a short line of text, to your domain's DNS settings at whoever hosts your domain.

  1. In the AI tool's admin settings, add your domain (for example the part after the @ in your staff emails).
  2. Copy the verification value it shows. On Claude it starts with anthropic-domain-verification- and is longer than the visible box, so use the copy button. Anthropic warns that once the domain shows as Pending, the console doesn't display the value again, so paste it somewhere safe first.
  3. At your DNS host, add a TXT record with that value.
  4. Wait, then press Verify or Refresh. Anthropic suggests about 10 minutes locally; OpenAI says DNS changes can take up to 24 hours to become visible. SSO setup in ChatGPT Business stays disabled until at least one domain is verified.

A filled-in record, as most DNS hosts display it, looks like this (the value is illustrative):

TypeHost / NameValueTTL
TXT@anthropic-domain-verification-7f3k2q9x...3600

Leave the record in place after verification. One caution from Anthropic's documentation: a verified domain belongs to the organisation that verified it, and another organisation can't claim it later. If a keen employee has already set up a Claude organisation on your domain, sort that out before you verify.

Stage 3: create the SAML connection (30-45 minutes)

SAML is the standard both sides use to trust each other. The AI tool gives you a few addresses; your identity provider gives you a certificate or metadata file. You paste each side's details into the other.

  • ChatGPT Business: as a workspace owner, open Workspace settings, then Identity & access, then Identity & provisioning. Under Single Sign-On (SSO), select Set up SSO and choose your provider (Okta, Entra ID, Google SAML, JumpCloud and others are listed, plus Custom SAML or Custom OIDC).
  • Claude Team: as an Owner or Primary Owner, open the organisation settings, choose Setup SSO and follow the guided flow, which Anthropic runs through its partner WorkOS, with specific guides for each identity provider. The Claude help centre article on SSO has the provider-by-provider steps.

The field names differ between providers, which is where most first attempts go wrong. This map covers the usual pairs:

What the AI tool showsWhere it goes in Google WorkspaceWhere it goes in Entra ID
ACS URLACS URLReply URL (Assertion Consumer Service URL)
Entity ID / AudienceEntity IDIdentifier (Entity ID)
Name ID should be emailName ID format: EMAIL; Name ID: Primary emailUnique User Identifier: user.mail or user.userprincipalname
Attributes: email, first name, last nameAttribute mappingAttributes & Claims
Upload metadata or certificateDownload IdP metadataFederation Metadata XML

Finally, assign access in the identity provider. In both Google and Entra ID only assigned users or groups can use the app. A group called something like "AI tools" makes later changes a one-click job.

Stage 4: test with one account before requiring SSO (20 minutes)

Leave SSO optional while you test. Run through this short plan and write down the result of each line:

  1. Assign one test user in the identity provider.
  2. In a private browser window, go to the AI tool, choose the SSO option and sign in with that user. Expected result: they land in your workspace, not a new personal account.
  3. Try a user who is not assigned. Expected result: refused.
  4. Sign in on the mobile app with the test user.
  5. Remove the test user from the group and try again. Expected result: refused.

Keep a way back in. Anthropic spells out the worst case: if Require SSO is on and your SAML certificate has already expired, no one in the organisation can sign in to update it, and you have to contact support from an Owner's email address. Put the certificate's expiry date in the shared calendar with a reminder a month ahead, and make sure at least two people hold the Owner role. On Claude, certificates are replaced under Authentication, then Manage SSO, then Metadata configuration, followed by Test sign-in.

Stage 5: require SSO and deal with existing accounts

Requiring SSO is where people get surprised, because it touches accounts they created before you started.

  • Claude: the Require SSO for Claude setting forces everyone on your verified domain to use the SSO option. People assigned to the SSO app keep access to any earlier Free, Pro, Team or Max accounts on that address and can switch between them. People not assigned lose access to those existing accounts while the requirement is on. A Restrict organisation creation setting also stops staff creating new Claude organisations on your domain.
  • ChatGPT Business: required SSO applies to members whose email uses a verified domain covered by the policy. Invited members from other domains, such as a freelancer on a personal address, can still use another permitted sign-in method, so SSO doesn't cover them.

Before you press the switch, run a last check. Filled in for the installer, it read:

  • Domain verified: yes, TXT record left in place.
  • Test user signed in on web and phone: yes.
  • Unassigned user refused: yes.
  • Everyone who should have access is in the "AI tools" group: 9 of 9.
  • Two Owners can sign in with SSO: yes (owner and office manager).
  • Certificate expiry in the calendar: yes, reminder a month ahead.
  • Staff told a week in advance: yes.

Give staff a week's notice with something like this:

From Monday 14th, you'll sign in to Claude with your work
Microsoft account (choose "Continue with SSO").

Before then, please:
- Export or copy anything you need from any personal Claude account
  that uses your work email address.
- Use only your work address for the team workspace.
- Tell me if you can't see the SSO option by Friday.

Your existing Team chats and projects won't change.

Provisioning without SCIM: invite-only or just-in-time

SCIM is the protocol that lets an identity provider create and remove accounts in another tool automatically. Neither ChatGPT Business nor Claude Team includes it; on OpenAI's side, tenant-wide SCIM needs an eligible Enterprise or Edu workspace, and on Anthropic's it is an Enterprise feature. That leaves two choices.

  • Invite only (the default on Claude, and the only route on ChatGPT Business): you invite each person in the AI tool, and SSO handles how they sign in. Most control, most admin.
  • Just-in-time (JIT), available on Claude Team: anyone assigned to the SSO app in your identity provider is added automatically on first sign-in, with the User role. Less admin, but Anthropic notes you give up control over exactly who joins, so keep the group assignment tight.

Seasonal staff show why the choice matters. Take an illustrative removals firm that adds six packers every summer and wants two of them, the crew leads, to use Claude for writing up inventory notes. With JIT and a broad "All staff" group assigned to the SSO app, all six would be added as members on first sign-in, and each paid seat would count. With a narrow "AI tools" group containing only the two crew leads, only they can join. At $25 a seat monthly, the difference over a three-month season is four unwanted seats, or $300.

For a small team, JIT plus a single "AI tools" group works well: adding someone to the group is the whole joiner process. Removal is still two steps. Taking someone out of the group stops their sign-in straight away, but their paid seat stays until you remove them in the AI tool. A monthly five-minute check of seat count against headcount catches the gap.

When the SSO login fails

These are the failures small teams hit most, with the fix for each:

  • "User not assigned to this application." The person isn't in the group or app assignment in the identity provider. Add them and try again after a minute.
  • They sign in but land in an empty personal workspace. Usually the email the identity provider sends doesn't match the one invited. Say an estimator signs in as sales@ because that alias is on his Microsoft account, while the workspace invited j.estimator@. Set Name ID to the primary address and invite that exact address.
  • The engineer on a personal Gmail can't see the SSO option. SSO only applies to your verified domain. Move them to a work address, then remove the old membership.
  • Everyone is suddenly refused on a Monday morning. Check the certificate expiry date first, then whether someone edited the SAML app in the identity provider.
  • A new starter gets "no seat available". On invite-only workspaces, SSO doesn't create seats. Add the seat, then the invite.

Once SSO works, turn on two-step verification in the identity provider itself, since it now guards every AI tool at once; two-factor authentication for AI accounts covers the options.

What it costs in money and time

ItemCostTime
SSO on ChatGPT Business or Claude TeamIncluded in the seat pricen/a
Identity provider (Google Workspace or Entra ID Free)Included in your existing plann/a
Conditional Access (optional, Entra ID P1)Included in Business Premium, $22/user/month annual1-2 hours to design rules
Domain verificationNothing15 minutes plus DNS wait
SAML setup and testing, per AI toolNothing1-1.5 hours
Staff switch-over and supportNothingAbout 10 minutes per person

For the nine-person installer, the whole job came to an afternoon: domain verification before lunch, the SAML app and tests after, and a notice to staff for the following Monday. The ongoing cost is the monthly seat check and one calendar reminder for the certificate.

SSO questions from small teams

Do we need SSO if we only use Copilot or Gemini?

No. Microsoft 365 Copilot and Copilot Chat run on your Microsoft 365 sign-in, and Gemini in Workspace runs on your Google Workspace sign-in, so blocking the work account already blocks the AI. SSO matters when you add a separately billed tool such as ChatGPT Business, Claude Team or Perplexity Enterprise Pro, which otherwise keeps its own passwords.

Is 'Continue with Google' the same as single sign-on?

Not quite. A 'Continue with Google' or Microsoft button on an individual plan is a convenience login that each person chooses. Admin SSO on a business plan is configured by you, tied to your verified domain and can be made compulsory, so an account you disable in your identity provider can no longer sign in to the AI workspace.

Will switching on SSO delete anyone's chats?

Switching on SSO doesn't delete workspace chats. The risk is personal accounts: on Claude, if you require SSO, people on your domain who aren't assigned to the SSO app lose access to their existing accounts, so ask staff to export anything they need first and assign everyone who should keep access before you flip the switch.

Further reads

Sources: OpenAI help centre (setting up SSO for ChatGPT Business; verifying your domain; SCIM availability); Claude help centre (set up single sign-on; considerations before enabling SSO and JIT/SCIM provisioning); Google Workspace Admin Help (set up your own custom SAML app); Microsoft Learn (Microsoft Entra single sign-on); vendor pricing pages, September 2026.

Want SSO set up without locking anyone out?

On a 1:1 call we'll check which of your AI tools can use SSO, map them to the identity provider you already have, and plan the switch-over so nobody loses access or chat history.

Book a 1:1 call with me