Set up single sign-on and SCIM
Single sign-on and SCIM come with Pellio Drive. They apply to signing in to your whole Pellio workspace, not just Drive. Owners and admins set them up in Settings → Security, in the Single sign-on card. Okta, Microsoft Entra ID, Google Workspace and any other SAML or OIDC provider work.
Add a connection
- Click Add a connection and choose the Protocol: SAML or OIDC.
- Enter your Email domain. People with addresses there sign in through this provider.
- For SAML, paste the Identity provider metadata (XML), or fill in the Sign-in URL (SSO URL), Issuer (entity ID) and Signing certificate. For OIDC, enter the Issuer URL (Pellio reads the rest from it), Client ID and Client secret.
- Click Add connection, then copy the values Pellio shows into your identity provider: the ACS (reply) URL and Entity ID (audience) and metadata URL for SAML, or the Redirect URI for OIDC.
For SAML, send the person’s email address as the attribute email and their name as displayName (or givenName and surname).
Verify your domain
A new connection shows Domain not verified, and nobody signs in through it until it’s verified. Add the TXT record shown (Name and Value) at your DNS provider, then click Check DNS. Once it’s found, the connection shows Verified. DNS changes can take a while to show up, so check again later if needed.
Signing in
On the Pellio log-in page, people click Sign in with SSO, enter their work email and click Continue with SSO. Their identity provider signs them in, and the first time they join your workspace.
Require single sign-on
Once a domain is verified, you can turn on Require single sign-on. Everyone at your verified domains must then sign in through your identity provider. Owners can still use their password, so you can’t be locked out. Remove on a connection lets those people sign in with a password or Google again.
Directory sync (SCIM)
Under Directory sync (SCIM), copy the SCIM base URL and click Make a SCIM token. Copy the token straight away: Pellio shows it only once. In your identity provider’s SCIM provisioning settings, enter the base URL and the token. Assigning someone the Pellio app adds them to your workspace; unassigning or deactivating them removes them. Owners are only ever changed in Pellio.
New token replaces the token (the old one stops working at once) and Turn off SCIM stops directory sync. People SCIM adds are workspace members; to give them Drive, an admin turns them on under Members on the Drive page.
Was this article helpful?
Related articles
- Get started with Pellio DriveStart the 14-day trial, make a filespace, choose who uses Drive and connect your first computer.
- Use the Pellio Drive app on Mac and WindowsInstall the app, mount filespaces, size the cache, pin files for offline work, and how saving and uploads work.
- Work with Drive files in the browserBrowse filespaces, upload and download, preview video, audio and images, and use versions and the trash.
- Share Drive files and request files with linksView links with a password, expiry and downloads on or off, and Request files links that let anyone send you files.