> ## Documentation Index
> Fetch the complete documentation index at: https://learn.nexudus.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Single sign-on

> Let customers and admins sign in to Nexudus with their company identity provider — Okta, Azure Active Directory, LDAP, or any OpenID Connect provider.

## Overview

Single sign-on (SSO) lets people sign in to your members portal — and optionally your dashboard — with an account they already have, such as their company Microsoft or Okta login, instead of a separate Nexudus password.

| Integration | Use it with |
| - | - |
| [**Azure Active Directory**](/integrations/sso/azure-active-directory) | Microsoft Entra ID (Azure AD), including Azure AD B2C. |
| [**Okta**](/integrations/sso/okta) | Okta, and identity providers connected to it such as Google or Microsoft. |
| [**OpenID**](/integrations/sso/openid) | Any OpenID Connect provider, such as Auth0. |
| [**LDAP**](/integrations/sso/ldap) | Your own LDAP directory server. |

All are free.

## Options every SSO integration shares

| Setting | What it does |
| - | - |
| **Create new users in Nexudus if they don't exist.** | When someone signs in through SSO without a Nexudus account, Nexudus creates one for them as a contact, using their name and email from the identity provider. When off, only people who already have a Nexudus account with the same email can sign in. |
| **Prevent users from using their Nexudus password to log in.** | Customers can only sign in to the members portal through SSO. |
| **Prevent users from using their Nexudus password to log in to this dashboard.** | Admins can only sign in to the dashboard through SSO. |
| **Sign in button label** | The text on the SSO button on your sign-in page, for example *Sign in with Microsoft*. |

<Warning>
  If you prevent Nexudus passwords **and** turn off creating new users, people without a Nexudus account can't get in at all. Test signing in as both a customer and an admin before turning off passwords.
</Warning>

A person's email in Nexudus must match their email in the identity provider.

## Related

* [Users and roles](/platform/settings/users-and-roles) — admin users
* [Integrations](/integrations/overview) — all integrations


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.