Claro + SAML SSO
Let employees sign in with the identity provider they already use, instead of managing another password.
Overview
Claro supports SAML 2.0 single sign-on so your organization's identity provider, such as Azure AD/Entra or Okta, becomes the single place employees authenticate. Each tenant configures its own identity provider settings independently, so a managed service provider or holding company running multiple Claro tenants can connect a different IdP per tenant without conflict. New users can be provisioned automatically on their first login through just-in-time provisioning, so there is no manual account-creation step before someone can access their training.
For organizations that want to fully retire local passwords, Claro offers an SSO-only enforcement option that requires authentication through the identity provider. This is useful when a tenant wants to guarantee that access to Claro follows the same identity governance as every other corporate application, including conditional access, multi-factor requirements, and centralized session control.
SSO reduces both friction and risk. Employees skip yet another password, which removes a common reason training goes uncompleted, and your security team removes a standalone credential that could be phished or reused. Because authentication happens at your identity provider, any control you already enforce there, such as blocking risky sign-ins or requiring MFA, automatically extends to Claro without separate configuration.
The integration is built on the SAML 2.0 standard rather than a single vendor, so any compliant identity provider works. Configuration is handled per tenant through metadata, an entry point, and a signing certificate, with attribute mapping that tells Claro how fields like email and name arrive from your IdP. For regulated environments, this centralized, standards-based approach makes access to Claro auditable alongside the rest of your identity estate.
How it works
Configure your identity provider
Add your IdP's metadata (entry point, certificate, or metadata URL) to Claro's per-tenant SSO settings so Claro can trust assertions from your provider.
Map user attributes
Define how identity provider attributes such as email and name map to Claro user fields, so provisioned accounts carry the right identity details.
Test the connection
Verify the SSO configuration with a test sign-in before rollout, confirming assertions validate and users land in Claro as expected.
Users sign in through the IdP
Employees authenticate with the identity provider and are signed into Claro, with new users provisioned automatically on first login if enabled.
Enforce SSO-only if required
Optionally require all sign-ins to go through the identity provider, retiring local passwords so Claro access follows the same governance as your other apps.
Frequently asked questions
Claro supports any SAML 2.0 compliant identity provider, including common ones like Azure AD/Entra and Okta, since the integration is built on the SAML 2.0 standard rather than a specific vendor.
Related pages
SCIM Provisioning
Automatically provision, update, and deactivate Claro user accounts and groups straight from your identity provider.
Learn moreSIEM
Feed phishing simulation and reporting signals into your SIEM so they sit alongside the rest of your security telemetry.
Learn moreLDAP / Active Directory
Sync your employee directory from LDAP or Active Directory so Claro's user list stays current, ideal for on-premise deployments.
Learn moreNot sure how Claro fits your stack?
Tell us what you run today and we will walk you through the integration path.
Request a demo