Bitfocus AS
logo
logo
Bitfocus AS
logo
logo
Sign upSign in

Loading...

Bitfocus

Subscribe to our newsletter

The latest news, articles, and resources, sent to your inbox.

FacebookInstagramGitHubYouTubeLinkedIn

Products

  • Buttons
  • Companion

Integrations

  • Supported Devices
  • Developer Community
  • Connection Development

Support

  • Support Overview
  • Documentation
  • Video Tutorials
  • Community Forum

Sales

  • Resellers & Integrators
  • Buttons Pricing

Updates

  • Case Studies
  • Events & Trade Shows
  • Press Releases
  • Product Updates
  • Webinars

Legal

  • Legal Overview
  • Privacy Policy
  • Buttons EULA
  • Terms & Cookie Policy

Company

  • About us
  • Press kit
  • Careers

© 2026 Bitfocus AS. All rights reserved.

Get started with SSO
Docs for
Overview
Getting started
What is Bitfocus Buttons?
Install Buttons and get started
Manage your Buttons license
Activate Buttons offline
Find your way around Buttons
Create your first backup
Add an ATEM connection
Choose a control method
Choose an installation path
Install Buttons on Debian or Ubuntu
Understand HA clustering
Kubernetes HA
Update or remove Buttons
Positions
Understand positions
Create a position
Add controls and sections to a position
Create your first button
Use a connection's presets
Build more capable button actions
Add more feedback to a button
Organize controls in a section
Shift Section
Organize controls with a Folder Section
Add a Popover Section
Build and reuse a Shared Section
Build a Router Section
Understand Custom Routers
Custom Router panel
Surfaces
Surface compatibility
Add and attach a surface
Device orientation
Connections
Update a connection's module safely
Monitor and troubleshoot a connection
Router integrations
VideoHub and AJA KUMO
Utah Scientific BPS
Generic SW-P-08
Nevion VideoIPath
Arkona BLADE//runner
Routing
Physical routing
Configure ports and labels
Take a physical route
Understand route status
Topology graph
Routing Presets
Get started with virtual routing
Configure Nested Shapes
Reverse routing
Tielines
Routing Projects
Routing settings
Troubleshoot a route
Tally
Understand the Tally system
Send ATEM tally and labels to a UMD
Interpret Active Tally state
TSL/UMD connections
Diagnose tally problems
NMOS
Understand NMOS in Buttons
Connect Buttons to an NMOS Registry
Built-in Registry Server
Configure NMOS connections
Discover and adopt
Browse the NMOS inventory
Manage NMOS multicast addresses
Diagnose NMOS problems
Understand Cuelists
Build a Cuelist
Read and advance a running Cuelist
Control a Cuelist from a Position
Workflows
Understand workflows
Build your first workflow
Reuse a group of workflow nodes safely
Troubleshoot a workflow
Recipes
Sequence a timed automation
Call an HTTP endpoint from a workflow
REST endpoint
Use variables
Understand variable scope
Understand nested variables
Update expressions for v1.8
Plan and use Tags
Access
Create and manage users
Create roles and assign permissions
Grant access to specific resources
Show different controls by role
Sessions
Set up PIN and NFC sign-in
SSO
Get started with SSO
Connect a generic OIDC provider
Connect LDAP or Active Directory
Map identity claims to roles
Secure a Buttons deployment
Integrations
External control
Connect to Bitfocus Listener
USB Relay
Install USB Relay on Windows
Install USB Relay on macOS
Install USB Relay on Linux
Install USB Relay on a Raspberry Pi
Get started with the Control API
Secure and monitor the Control API
Control API reference
API reference
Administration
Enable and manage installable features
Services and health
Configure and monitor scheduled backups
Restore a backup and verify it
Export or import Buttons configuration
Store and rotate connection secrets
Replace the HTTPS certificate
HA backup and recovery
Settings
Collect support information
Reference
Glossary
Button Inspector reference
Network ports reference
Expressions
Internal actions reference
Routing Presets panel reference
Startup configuration reference
Workflow nodes
Connection workflow nodes
Workflow workflow nodes
Internal workflow nodes
Position workflow nodes
API workflow nodes
Utility workflow nodes

Loading...

Previous
← Set up PIN and NFC sign-in
Next
Connect a generic OIDC provider →
Contact support →
You are viewing documentation for Buttons 1.8.See the docs for Buttons 1.6
Buttons/Access/SSO/Get started with SSO

Get started with SSO

Single Sign-On lets people sign in to Buttons through an identity provider your organization already uses, instead of maintaining a separate local password. This page covers the shared setup that applies no matter which provider you connect, and the safe order to bring it online.

Important

Local username/password sign-in can never be disabled through SSO configuration. It's not a setting you might accidentally turn off: the code path that handles local sign-in has no dependency on SSO at all. Whatever happens with your identity provider, the local sign-in option stays reachable from the same login page.

Before you begin#

  • An Enterprise license: SSO is gated to this tier, and only system administrators can configure it.
  • A plan for at least one role your identity provider's claims or groups should map to: see Map identity claims to roles.

Understand the page#

Settings → SSO ("SSO connections") has two parts:
  • Sign-in policy: a master SSO login toggle ("Allow users to sign in with configured identity providers."), a Default login choice of which sign-in view loads first, local or SSO (you can't actually set this to SSO until at least one provider exists), and Allowed email domains: an optional allowlist restricting which email domains can register a new account through SSO (leave it empty to allow any domain). Both sign-in views remain reachable regardless of the default: that setting only changes which one someone sees without clicking through.
  • Identity providers: the list of configured connections, added via Add provider. You can add more than one: Google, Microsoft Entra ID, GitHub, Okta, Generic OIDC, and LDAP/Active Directory can all coexist, each enabled independently.

Bring SSO online safely#

  1. Add a connection for your provider: see Connect a generic OIDC provider or Connect LDAP or Active Directory for the provider-specific fields.
  2. Add at least one role mapping before you expect anyone to actually use it: see Map identity claims to roles. Without a mapping, a successful sign-in still won't grant any role.
  3. Sign in yourself as a real test of the whole path. Only LDAP has a built-in Test connection check (a service-account bind and search): for every other provider, an actual sign-in is the only way to confirm the whole chain works, since there's no separate pre-flight test.
  4. Only once that works, turn on the master SSO login toggle and, if you want it to be what people see first, switch the default sign-in view to SSO.
Until the master toggle is on, the interface reminds you directly: "Local login remains active until SSO login is enabled." Turning it on adds SSO as an option: it never removes or restricts local sign-in.

Know what isn't a safety net#

There's no separate "rollback" feature to reach for if something goes wrong: no watchdog-level override, no external kill switch. The reason you don't need one is architectural: local sign-in was never dependent on SSO in the first place, so there's nothing to roll back to. Keep a local administrator account's credentials on hand as ordinary good practice, not because Buttons would otherwise lock you out.

If you get stuck#

What you see
What to try
A user signs in through SSO but gets no role.
Add a role mapping that actually matches their claims: see Map identity claims to roles.
You're not sure SSO is configured correctly before turning it on for everyone.
Sign in yourself as a real test: beyond LDAP's own connection check, this is the only way to confirm the full path works.
You're worried about being locked out while testing.
You won't be: local sign-in is never disabled by anything in this settings area, at any point.
The SSO login toggle is off and users are asking why SSO isn't available yet.
That's expected until you turn it on deliberately, once you've verified the connection and its role mappings work.
A user can authenticate with your identity provider but still can't get an account.
Check Allowed email domains, if it's set, only matching email domains can register a new account through SSO; leave it empty to allow any domain.

Where to go next#

  • Connect a generic OIDC provider
  • Connect LDAP or Active Directory
  • Map identity claims to roles

Was this helpful?

Was this helpful?

0 of 0 users found this page helpful