How do I set up Single Sign-On (SSO) for my N.Rich account?
Last updated: October 6, 2026
Single Sign-On (SSO) lets your team log in to N.Rich with your company's identity provider (IdP) instead of a separate N.Rich email and password. SSO is a paid add-on to your N.Rich plan.
How it works
N.Rich supports SAML-based SSO, connected through our identity provider, Auth0. It works with standard SAML-compliant identity providers, including Okta, Microsoft Entra ID (Azure AD), OneLogin and Google Workspace.
The first time someone logs in through SSO, N.Rich creates their user account and gives them the Analytics role.
We set up your first Admin at go-live. From then on, any Admin can change roles in Manage users. See Inviting team members and setting user roles.
Roles are managed in N.Rich, not in your identity provider. We don't read groups or roles from your SAML assertion.
Set up SSO
Confirm with your Account Manager that SSO should be enabled for your account. Pricing is agreed per account before we enable it.
Your IT team sets up N.Rich as an application in your identity provider and sends us the connection details (see "What we need from you" below).
We configure and test the connection on our side.
We confirm with you that it's ready and support your team through the first logins.
What we need from you
Not every item applies to every identity provider. Send us what applies to yours and we'll tell you if anything is missing:
Your identity provider type (for example Microsoft Entra ID, OneLogin, Google Workspace or Okta)
The sign-in URL, sometimes called the SAML 2.0 endpoint
The sign-out URL, if you want single logout (optional)
Your IdP Entity ID (the issuer URI), if your provider requires one
Your X.509 token signing certificate, PEM-encoded
The company email domains your team logs in with, for example yourcompany.com
The names your provider uses for email, given name and family name in the SAML assertion
In return, we give your IT team the values they need on their side, including an Identifier (Entity ID) and a Reply URL (Assertion Consumer Service / ACS URL). These are specific to your connection, so we share them directly.
If your team already uses email and password
We replace those logins as part of the switch. We agree the list of users with you first and time it so everyone moves over at once. From then on, everyone signs in through your identity provider.
What to expect
SSO is usually live about four weeks after your IT team has sent us all the details. Every identity provider is set up a little differently, so we include one support session at go-live to sort out any first-login issues.
Good to know
Session timeout: N.Rich signs users out after 30 minutes of inactivity, with or without SSO. This is a platform-wide setting and can't be changed per account.
Removing users isn't automatic: SSO creates new users on their first login, but it doesn't remove people who leave your company. An Admin removes them in Manage users, or you can reach out to your Solutions Engineer.
What's next
Inviting team members and setting user roles: see what each role can do and how Admins change roles.
Need help? Reach out to your Solutions Engineer via the chat in the bottom-left corner of the N.Rich platform, by email or Slack.