You need three things: a business AI plan that offers SSO (ChatGPT Business, Claude Team or Perplexity Enterprise Pro), an identity provider you already pay for (Google Workspace or Microsoft Entra ID), and access to your domain's DNS. Verify the domain, create a SAML app, test one account, then require SSO. Budget two to three hours.
Single sign-on (SSO) means staff sign in to the AI tool with their normal work account instead of a separate password. It fixes sign-in, not membership: ChatGPT Business and Claude Team have no SCIM directory sync, so adding and removing seats stays manual. And Microsoft 365 Copilot and Gemini in Workspace need no SSO at all, because they already run on your work identity.
Which AI plans support SSO, and what each leaves out
Before touching any settings, check your plan. SSO is a workspace feature, so individual subscriptions such as ChatGPT Plus or Claude Pro don't offer it. A "Continue with Google" button on those plans is a login each person chooses for themselves, not something an admin controls.
| Tool and plan | SSO | Automatic user sync (SCIM) | Notes |
|---|---|---|---|
| ChatGPT Business ($25/user/month monthly, $20 annual, 2-seat minimum) | Yes, SAML or OIDC | No | Invites and seat removal are manual |
| ChatGPT Enterprise (custom quote) | Yes | Yes | Group sync through your identity provider |
| Claude Team ($25/seat monthly, $20 annual, 2-seat minimum) | Yes, SAML | No; just-in-time provisioning instead | Supports Okta, Entra ID, Google, OneLogin, JumpCloud, Duo |
| Claude Enterprise | Yes | Yes | Role mapping by group, automatic removal |
| Perplexity Enterprise Pro ($40/seat/month) | Yes | Yes | Also adds admin controls and internal file search |
| Microsoft 365 Copilot, Copilot Chat | Not needed | Not needed | Uses your Microsoft 365 sign-in |
| Gemini in Google Workspace | Not needed | Not needed | Uses your Workspace sign-in |
If your team is still on shared or personal ChatGPT logins, the plan question comes first; when a shared ChatGPT plan stops being enough covers that decision, and whether Claude Team is worth it does the same for Anthropic's plan.
What SSO changes for a nine-person HVAC installer
Consider an illustrative heating and air-conditioning installer with nine staff on Microsoft 365 and ChatGPT Business. Before SSO, each person had a ChatGPT password. Two engineers had joined the workspace with personal Gmail addresses because that is what their phones were signed in with. When a service coordinator left, her Microsoft 365 account was blocked the same afternoon, but she could still sign in to ChatGPT from home for three weeks, because nobody remembered it had its own password. She had a project full of customer addresses and maintenance contract notes.
After SSO, everyone signs in to ChatGPT through Microsoft. Blocking a Microsoft 365 account now blocks ChatGPT sign-in at the same moment. The two Gmail users were moved to work addresses during the switch-over. What SSO didn't change: the leaver's seat still sat on the invoice until the owner removed it in ChatGPT's member settings. At $25 a month on monthly billing, a seat forgotten for a quarter costs $75, which is why SSO belongs alongside a proper staff offboarding checklist, not instead of one.
Stage 1: pick the identity provider you already have (20 minutes)
An identity provider is the system that holds your staff accounts and vouches for them. Most small businesses already have one without calling it that.
- Google Workspace. A super administrator can add a custom SAML app under Apps, then Web and mobile apps, then Add app, then Add custom SAML app. You then choose which users or groups can use it.
- Microsoft Entra ID (the directory behind Microsoft 365). The free tier included with Microsoft 365 business plans supports SAML single sign-on to SaaS apps. Look for the AI tool in the Enterprise applications gallery; if it isn't listed, create your own non-gallery application. Conditional Access rules, such as allowing sign-in only from company laptops, need Entra ID P1, which Microsoft 365 Business Premium ($22/user/month annual) includes.
- Okta, JumpCloud or similar. If you already run one, use it; both ChatGPT Business and Claude Team list them as supported.
Pick one. Running SSO for ChatGPT through Google and for Claude through Microsoft doubles the places a leaver must be removed from.
Stage 2: verify your domain (15 minutes, plus the DNS wait)
Both OpenAI and Anthropic make you prove you own your email domain before SSO can be set up. You do that by adding a TXT record, a short line of text, to your domain's DNS settings at whoever hosts your domain.
- In the AI tool's admin settings, add your domain (for example the part after the @ in your staff emails).
- Copy the verification value it shows. On Claude it starts with
anthropic-domain-verification-and is longer than the visible box, so use the copy button. Anthropic warns that once the domain shows as Pending, the console doesn't display the value again, so paste it somewhere safe first. - At your DNS host, add a TXT record with that value.
- Wait, then press Verify or Refresh. Anthropic suggests about 10 minutes locally; OpenAI says DNS changes can take up to 24 hours to become visible. SSO setup in ChatGPT Business stays disabled until at least one domain is verified.
A filled-in record, as most DNS hosts display it, looks like this (the value is illustrative):
| Type | Host / Name | Value | TTL |
|---|---|---|---|
| TXT | @ | anthropic-domain-verification-7f3k2q9x... | 3600 |
Leave the record in place after verification. One caution from Anthropic's documentation: a verified domain belongs to the organisation that verified it, and another organisation can't claim it later. If a keen employee has already set up a Claude organisation on your domain, sort that out before you verify.
Stage 3: create the SAML connection (30-45 minutes)
SAML is the standard both sides use to trust each other. The AI tool gives you a few addresses; your identity provider gives you a certificate or metadata file. You paste each side's details into the other.
- ChatGPT Business: as a workspace owner, open Workspace settings, then Identity & access, then Identity & provisioning. Under Single Sign-On (SSO), select Set up SSO and choose your provider (Okta, Entra ID, Google SAML, JumpCloud and others are listed, plus Custom SAML or Custom OIDC).
- Claude Team: as an Owner or Primary Owner, open the organisation settings, choose Setup SSO and follow the guided flow, which Anthropic runs through its partner WorkOS, with specific guides for each identity provider. The Claude help centre article on SSO has the provider-by-provider steps.
The field names differ between providers, which is where most first attempts go wrong. This map covers the usual pairs:
| What the AI tool shows | Where it goes in Google Workspace | Where it goes in Entra ID |
|---|---|---|
| ACS URL | ACS URL | Reply URL (Assertion Consumer Service URL) |
| Entity ID / Audience | Entity ID | Identifier (Entity ID) |
| Name ID should be email | Name ID format: EMAIL; Name ID: Primary email | Unique User Identifier: user.mail or user.userprincipalname |
| Attributes: email, first name, last name | Attribute mapping | Attributes & Claims |
| Upload metadata or certificate | Download IdP metadata | Federation Metadata XML |
Finally, assign access in the identity provider. In both Google and Entra ID only assigned users or groups can use the app. A group called something like "AI tools" makes later changes a one-click job.
Stage 4: test with one account before requiring SSO (20 minutes)
Leave SSO optional while you test. Run through this short plan and write down the result of each line:
- Assign one test user in the identity provider.
- In a private browser window, go to the AI tool, choose the SSO option and sign in with that user. Expected result: they land in your workspace, not a new personal account.
- Try a user who is not assigned. Expected result: refused.
- Sign in on the mobile app with the test user.
- Remove the test user from the group and try again. Expected result: refused.
Keep a way back in. Anthropic spells out the worst case: if Require SSO is on and your SAML certificate has already expired, no one in the organisation can sign in to update it, and you have to contact support from an Owner's email address. Put the certificate's expiry date in the shared calendar with a reminder a month ahead, and make sure at least two people hold the Owner role. On Claude, certificates are replaced under Authentication, then Manage SSO, then Metadata configuration, followed by Test sign-in.
Stage 5: require SSO and deal with existing accounts
Requiring SSO is where people get surprised, because it touches accounts they created before you started.
- Claude: the Require SSO for Claude setting forces everyone on your verified domain to use the SSO option. People assigned to the SSO app keep access to any earlier Free, Pro, Team or Max accounts on that address and can switch between them. People not assigned lose access to those existing accounts while the requirement is on. A Restrict organisation creation setting also stops staff creating new Claude organisations on your domain.
- ChatGPT Business: required SSO applies to members whose email uses a verified domain covered by the policy. Invited members from other domains, such as a freelancer on a personal address, can still use another permitted sign-in method, so SSO doesn't cover them.
Before you press the switch, run a last check. Filled in for the installer, it read:
- Domain verified: yes, TXT record left in place.
- Test user signed in on web and phone: yes.
- Unassigned user refused: yes.
- Everyone who should have access is in the "AI tools" group: 9 of 9.
- Two Owners can sign in with SSO: yes (owner and office manager).
- Certificate expiry in the calendar: yes, reminder a month ahead.
- Staff told a week in advance: yes.
Give staff a week's notice with something like this:
From Monday 14th, you'll sign in to Claude with your work
Microsoft account (choose "Continue with SSO").
Before then, please:
- Export or copy anything you need from any personal Claude account
that uses your work email address.
- Use only your work address for the team workspace.
- Tell me if you can't see the SSO option by Friday.
Your existing Team chats and projects won't change.
Provisioning without SCIM: invite-only or just-in-time
SCIM is the protocol that lets an identity provider create and remove accounts in another tool automatically. Neither ChatGPT Business nor Claude Team includes it; on OpenAI's side, tenant-wide SCIM needs an eligible Enterprise or Edu workspace, and on Anthropic's it is an Enterprise feature. That leaves two choices.
- Invite only (the default on Claude, and the only route on ChatGPT Business): you invite each person in the AI tool, and SSO handles how they sign in. Most control, most admin.
- Just-in-time (JIT), available on Claude Team: anyone assigned to the SSO app in your identity provider is added automatically on first sign-in, with the User role. Less admin, but Anthropic notes you give up control over exactly who joins, so keep the group assignment tight.
Seasonal staff show why the choice matters. Take an illustrative removals firm that adds six packers every summer and wants two of them, the crew leads, to use Claude for writing up inventory notes. With JIT and a broad "All staff" group assigned to the SSO app, all six would be added as members on first sign-in, and each paid seat would count. With a narrow "AI tools" group containing only the two crew leads, only they can join. At $25 a seat monthly, the difference over a three-month season is four unwanted seats, or $300.
For a small team, JIT plus a single "AI tools" group works well: adding someone to the group is the whole joiner process. Removal is still two steps. Taking someone out of the group stops their sign-in straight away, but their paid seat stays until you remove them in the AI tool. A monthly five-minute check of seat count against headcount catches the gap.
When the SSO login fails
These are the failures small teams hit most, with the fix for each:
- "User not assigned to this application." The person isn't in the group or app assignment in the identity provider. Add them and try again after a minute.
- They sign in but land in an empty personal workspace. Usually the email the identity provider sends doesn't match the one invited. Say an estimator signs in as
sales@because that alias is on his Microsoft account, while the workspace invitedj.estimator@. Set Name ID to the primary address and invite that exact address. - The engineer on a personal Gmail can't see the SSO option. SSO only applies to your verified domain. Move them to a work address, then remove the old membership.
- Everyone is suddenly refused on a Monday morning. Check the certificate expiry date first, then whether someone edited the SAML app in the identity provider.
- A new starter gets "no seat available". On invite-only workspaces, SSO doesn't create seats. Add the seat, then the invite.
Once SSO works, turn on two-step verification in the identity provider itself, since it now guards every AI tool at once; two-factor authentication for AI accounts covers the options.
What it costs in money and time
| Item | Cost | Time |
|---|---|---|
| SSO on ChatGPT Business or Claude Team | Included in the seat price | n/a |
| Identity provider (Google Workspace or Entra ID Free) | Included in your existing plan | n/a |
| Conditional Access (optional, Entra ID P1) | Included in Business Premium, $22/user/month annual | 1-2 hours to design rules |
| Domain verification | Nothing | 15 minutes plus DNS wait |
| SAML setup and testing, per AI tool | Nothing | 1-1.5 hours |
| Staff switch-over and support | Nothing | About 10 minutes per person |
For the nine-person installer, the whole job came to an afternoon: domain verification before lunch, the SAML app and tests after, and a notice to staff for the following Monday. The ongoing cost is the monthly seat check and one calendar reminder for the certificate.
SSO questions from small teams
Do we need SSO if we only use Copilot or Gemini?
No. Microsoft 365 Copilot and Copilot Chat run on your Microsoft 365 sign-in, and Gemini in Workspace runs on your Google Workspace sign-in, so blocking the work account already blocks the AI. SSO matters when you add a separately billed tool such as ChatGPT Business, Claude Team or Perplexity Enterprise Pro, which otherwise keeps its own passwords.
Is 'Continue with Google' the same as single sign-on?
Not quite. A 'Continue with Google' or Microsoft button on an individual plan is a convenience login that each person chooses. Admin SSO on a business plan is configured by you, tied to your verified domain and can be made compulsory, so an account you disable in your identity provider can no longer sign in to the AI workspace.
Will switching on SSO delete anyone's chats?
Switching on SSO doesn't delete workspace chats. The risk is personal accounts: on Claude, if you require SSO, people on your domain who aren't assigned to the SSO app lose access to their existing accounts, so ask staff to export anything they need first and assign everyone who should keep access before you flip the switch.
Further reads
- How to Set Up Company AI Accounts Instead of Personal Logins — Move staff off personal AI logins before you add SSO.
- ChatGPT Plus vs ChatGPT Business: Which Plan Does a Team Need? — SSO is one of the reasons to move from Plus to Business.
- How to Share AI Tool Logins Safely With a Password Manager — For the tools that will never support SSO.
- AI Security Checklist Before Connecting Tools to Email and Files — The other controls to set while you are in the admin console.
- How to Check Which Apps Can Access Your Business Accounts — Audit what else signs in with your work accounts.
- How to Onboard New Hires Onto Your AI Tools and Rules — A first-month plan for new starters on your AI tools: accounts before day one, one-page rules, buddy-checked tasks and a sign-off for wider access.
- Questions to Ask Before Buying AI That Touches Client Data — Nineteen questions to put to any AI vendor before client files go in, with what a good answer looks like and the replies that should stop a purchase.
- How to Connect ChatGPT or Claude to Your Business Apps — ChatGPT apps, Claude connectors, custom MCP and Zapier routes compared, with a wedding planner's setup and the permissions to set first.
- Is ChatGPT Safe for Business Use? Risks, Settings and Plan Choice — The five real risks of using ChatGPT at work, the settings that fix most of them, and which plan fits a sole trader, a small team or a clinic.
- AI Consultant vs Your IT Support Company: Who Should Handle AI? — Who should handle which parts of AI: a task-by-task split between your IT provider and a consultant, with a wine merchant's Copilot pilot.
- How to Choose a Managed IT Provider That Can Support AI Tools — A two-site garage's AI tools, eight questions for IT providers and a first-month audit that found six problems: how to pick an MSP that can support AI properly.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: OpenAI help centre (setting up SSO for ChatGPT Business; verifying your domain; SCIM availability); Claude help centre (set up single sign-on; considerations before enabling SSO and JIT/SCIM provisioning); Google Workspace Admin Help (set up your own custom SAML app); Microsoft Learn (Microsoft Entra single sign-on); vendor pricing pages, September 2026.