Organization SSO
SSO (single sign-on) lets your co-workers sign in to Retyc with your company identity provider (Entra ID / Azure AD, Okta, Keycloak...), rather than with a Retyc password. Your internal rules then apply to sign-in: password policy, enforced MFA, centralized access revocation.
Organization SSO is a plan option. To set it up, contact the sales team: the configuration is carried out with the Retyc team.
How does it work?
- One or more email domains are reserved for your organization.
- Users from these domains are automatically routed to your identity provider at sign-in time.
- Accounts created through SSO are managed by the organization: a co-worker disabled in your directory can no longer sign in to Retyc.
End-to-end encryption is independent from authentication: the personal encryption key and its passphrase remain each user's own, even when signing in through SSO.
View the configuration
The Dashboard > Organization > SSO tab shows a read-only view of the configuration: status (active or inactive), connected identity providers and the domains reserved for your organization. Any change goes through the Retyc team.