Single sign-on without the enterprise contract
SAML 2.0 and OIDC single sign-on is available from Starter up, not held back for a custom-priced tier. One login for the team, and a billing model that does not punish you for it.
Standard protocols (Starter+)
SAML 2.0 and OIDC, the two protocols your identity provider already speaks: Microsoft Entra ID, Google Workspace, Okta and the rest. No proprietary connector to license.
A gate that cannot drift
The plan that unlocks single sign-on is read from the live plan catalogue, on this page and everywhere else on this site. What the pricing page says is what the application enforces.
SSO does not change your bill
A sign-in through single sign-on counts exactly like a password sign-in: once per person per billing month. Some vendors price federated users differently. This one does not.
Provisioning when you are ready
Automated user provisioning and deprovisioning over SCIM sits on Enterprise, for the day your directory, not a spreadsheet, should decide who has an account.
Questions identity teams ask
- Which single sign-on protocols does EmbayLMS support?
- SAML 2.0 and OIDC, available from Starter up. They cover Microsoft Entra ID, Google Workspace, Okta and any other standards-compliant identity provider.
- Does single sign-on change how users are billed?
- No. An active user is someone who signs in at least once during the billing month. A sign-in through SAML or OIDC counts exactly the same as a password sign-in, once per billing month.
- Is SCIM provisioning included with SSO?
- They are separate capabilities. Single sign-on is available from Starter up; SCIM provisioning sits on Enterprise. The pricing page reads both gates from the same catalogue the application enforces.