Configure the identity provider
- Open Settings → Access and review the values Tekma displays for ACS URL and Service provider entity ID.
- Create a SAML application in Okta, Microsoft Entra ID, Google Workspace, or another compatible provider using those values. Send a signed assertion with email and name attributes, a stable NameID, audience, recipient and timestamp conditions. Use SHA-256 or stronger.
- In Tekma, enter the Company email domain, Identity provider entity ID, and Identity provider sign-in URL. Paste the provider’s public signing certificate in PEM format; never paste a private key.
- Choose Save SAML configuration. Saving or replacing configuration disables SSO until DNS is verified again.
Verify and enable
Publish the_tekma-saml DNS proof shown by Tekma for the exact company domain. The proof is valid for seven days. Choose Verify DNS and enable SSO. Reverify the same record when it expires or when Tekma asks after a configuration change.
Test the SP-initiated company sign-in in a separate window before directing teammates to it. Existing verified members can use company sign-in when the deployment enables that path. Password sign-in and Tekma MFA remain available; Tekma continues to manage membership and roles.