PLANS / configure-sso-for-grok-organization

Plans

Configure SSO for a Grok organization

Configure SSO for a Grok organization

Enterprise organizations centralize login at console.x.ai/organization. Organization admins wire Single Sign-On (SSO) to their IdP there. Official guide: Organization Management.

Organizations are Enterprise-only. Contact xAI sales if the /organization page is unavailable.

Configure

  1. Open console.x.ai/organization as an organization admin.
  2. Click Configure SSO.
  3. Pick your IdP from the supported list (Okta, Azure AD, Google Workspace, and others shown in the console).
  4. Follow the IdP-specific instructions in the console — metadata exchange and attribute mapping are spelled out per provider.
  5. Save the configuration and run the built-in SSO test.

After activation

SSO is enforced organization-wide once configured.

  • Users authenticate through SSO on their next access.
  • Choosing Log in with email with a domain-associated address (for example @yourcompany.com) redirects to your IdP.
  • Addresses outside the linked domain keep standard login methods.

Tell the org before rollout so people expect the IdP redirect.

Domain association

Link the organization to a company email domain on the same dashboard. Signups and logins from that domain associate with the organization automatically. Admins can list every domain-associated user and their team affiliations under Users, and review linked console teams under Teams.

Pitfalls

  • Non-admin accounts cannot open /organization — ask an organization admin.
  • Testing only in the console is not enough for rollout; verify a real domain user hits the IdP on next login.
  • Outside-domain emails will still use password/social login; that is expected.