SAML SSO is included on the Enterprise plan. We support Google Workspace, Microsoft Entra ID (formerly Azure AD), Okta, OneLogin, and any IdP that speaks SAML 2.0.
Configure
Settings > Security > SSO. Pick your IdP, follow the per-IdP wizard. Upload the IdP metadata XML, copy the Message ACS URL into your IdP, map attributes (email, name, role, department).
Test
Once configured, the Test SSO button verifies the round-trip. Errors are surfaced with the exact SAML response that came back. Fix and re-test.
SCIM
SCIM 2.0 auto-provisioning is supported on Enterprise. Add or remove an agent in your IdP and the change reflects in Message within 5 minutes.