Integrate with your company's authentication system to enable logins. Dive supports two methods: Microsoft Entra ID (OIDC) and SAML 2.0. If you want to centralize user management through SSO, also enable "Disallow logins other than SSO".
Available Plans
This feature is available on the Enterprise Plan.
Who Can Configure
Only users with Owner permission.
Differences Between the Two Methods
| Method | Target IdP | Setup |
|---|---|---|
| Method 1: Microsoft Entra ID (OIDC) | Microsoft 365 / Azure AD | You can set up yourself (Integration per tenant) |
| Method 2: SAML 2.0 | Okta / Azure AD / OneLogin / HENNGE One and more | Dive Customer Success configures individually (Prepare IdP metadata XML and more) |
Common Configuration Steps
- Open "Owner Functions" in the side menu
- Select the "Security" tab at the top and open the "Single Sign-On (SSO) Settings" card
- Check "Enable"
Method 1: Microsoft Entra ID (OIDC) Integration
Integrate at the tenant level with Microsoft 365 / Azure AD. You can set it up yourself.
- Expand "[Microsoft Entra ID (OIDC) Integration]"
- Click "+ Sign in with Microsoft account and integrate with the associated tenant"
- On the Microsoft sign-in screen, sign in with the administrator account of the tenant you want to integrate
- On the screen that returns, the tenant information (domain and tenant ID) is added to the "Connected Tenants List"
- Click "Save"
※ Free email services (gmail.com, outlook.com, etc.) and shared domains are not eligible for integration. Use your organization's unique domain.
Method 2: SAML 2.0 Integration
You can integrate with SAML 2.0 IdPs such as Okta / Azure AD / OneLogin / HENNGE One. Dive Customer Success configures this individually.
- Expand "[SAML 2.0 Integration]"
- Prepare the necessary information on the IdP side (metadata XML / SSO URL / certificate, etc.) and contact us at customer-success@episotech.com
- After configuration is complete, the domains currently integrated with SAML will be displayed on the screen
※ SAML 2.0 integration is not available during the trial period. It will be available after the formal contract begins. If you are considering implementation, please contact us in advance.
Disallow Logins Other Than SSO
If you want to centralize user management through SSO, check "Disallow logins other than SSO" and save.
When enabled, only the SSO button will be displayed on the Dive login screen, and logins with ID and password will no longer be accepted.
Users Not Targeted
- Email-free accounts (ID logins issued by administrators) cannot use SSO and are excluded from this restriction
Tips
- Always test before enabling SSO enforcement: Verify with a test user that "SSO button → successful login → transition to Dive screen" works before enabling
- Organize tenants: If you use multiple Microsoft tenants, explicitly organizing integration targets reduces problems
- SAML requires advance consultation: Since contract type and IdP information preparation take time, consult with us early if you plan to implement
- MFA for SSO users: SSO users are expected to have MFA managed on the IdP side. They are excluded from Dive's MFA enforcement setting