TimeLeafTimeLeaf
Back to site

Security & Compliance

SSO Configuration

Let employees sign in with their existing identity provider. TimeLeaf supports Microsoft 365 / Entra ID and Google Workspace.

SSO is available on Professional plans and above. TimeLeaf does not support SAML — identity providers like Okta, OneLogin, or PingIdentity are not available.

Supported providers

Microsoft 365 / Entra ID (Professional+) Employees sign in with their Microsoft work account. Requires the Microsoft 365 integration to be connected first.

Google Workspace (Professional+) Employees sign in with their Google Workspace account. Requires the Google Workspace integration to be connected first.

Enabling Microsoft or Google SSO

Once the Microsoft 365 or Google Workspace integration is connected (see Integrations section), go to Settings -> Security -> Single Sign-On and toggle Enable SSO for the provider.

You can choose whether SSO is optional (employees can still use email/password) or required (password login is disabled for all employees).

Just-in-time provisioning

With JIT provisioning enabled, new employees who sign in via SSO are automatically created in TimeLeaf with the Employee role and assigned the default leave policy. No manual invite needed.