# Identity and access management

Use Identity and access management to configure and understand organization SSO.

> This section only applies to organizations with Okta SSO enabled.
Organizations without Okta SSO enabled can continue using the normal Mabyduck
sign-in methods available to their users, such as email and connected identity
providers.
Speak to [support@mabyduck.com](mailto:support@mabyduck.com) if you're interested in enabling Okta.


## Okta sign in

For Okta enabled organizations, users can sign in from the Mabyduck tile in Okta
or from:

`https://app.mabyduck.com/org/{org-slug}/`

Returning Okta-managed users who start at `https://app.mabyduck.com/login` are
redirected when Mabyduck can identify their organization.

This redirect works after the user has signed in through either the
IdP-initiated or SP-initiated flow once.

## Existing users

> Each Mabyduck user can only belong to one organization.


Existing Mabyduck users keep their projects, experiments, datasets, and history
when Okta is enabled for their organization.

After they join an Okta-enabled organization, the following sign-in methods no
longer bypass the organization's Okta requirement:

- Email + password (including 2FA).
- Google login.
- GitHub login.


Before asking a user to sign in, confirm:

- the user is assigned to the Mabyduck app in Okta.
- the user belongs to the Mabyduck organization.
- their Okta email matches their Mabyduck email.
- they have the organization login URL or Okta tile.


## App assignments

Assign the Mabyduck app in Okta to the users or groups who should sign in.

Remove the app assignment to block future sign-in.

## Removing access

For Okta-enabled organizations, remove access in both systems:

1. Remove the user's Mabyduck app assignment in Okta.
2. Remove the user from the Mabyduck organization.
3. Use [Universal Logout](/account-and-settings/iam/universal-logout) if Okta should end active
Mabyduck sessions.


## Supported features

- organization Okta SSO (IdP)
- Okta dashboard tile sign-in (IdP-initiated SSO)
- organization login URL sign-in (SP-initiated SSO)
- Okta app assignment as the sign-in gate
- Just-in-Time (JIT) user creation on first valid Okta sign-in
- Universal Logout


## Related pages

- [Configure Okta SSO](/account-and-settings/iam/okta)
- [Universal Logout](/account-and-settings/iam/universal-logout)
- [Okta SSO troubleshooting](/account-and-settings/iam/sso-troubleshooting)