Documentation

Identity Providers (IdP — SSO & Provisioning)

SURF supports SSO login and user/group provisioning through the identity providers below. Each is configured under Settings → Integrations; fields shown are entered in the integration's setup dialog.

  • Microsoft Entra ID / Azure AD — SAML 2.0 or OIDC (incl. Azure AD B2C). SSO + JIT user creation; a SAML group claim can place users into a matching SURF group. Config — SAML: Sign-on URL, Entity ID, signing certificate · OIDC: Client ID, Client Secret, Tenant ID.
  • Generic SAML 2.0 — any SAML IdP. Config: Entity ID, Sign-on URL, signing certificate, binding (Redirect/POST), optional attribute→group mapping (dynamic user association).
  • Okta — SSO (SAML / Okta widget) plus Okta Users API enrichment. Config: Okta org URL/domain, API token.
  • Google Workspace — Google OAuth/OIDC sign-in; users matched by email.
  • Windows AD / LDAP (on-prem) — username/password against on-prem AD via the SURF Windows-AD bridge; supports JIT one-time AD passwords. Config: bridge host (DNS), API key.
  • SCIM 2.0 provisioning — IdP-agnostic user/group provisioning & deprovisioning (Okta, Entra, …) via /scim/v2. Config: SCIM bearer token (per company).
  • Duo — MFA provider, used alongside an IdP.
JumpCloud and OneLogin are not first-class providers — onboard them through Generic SAML 2.0 or SCIM 2.0.