Skip to main content
This guide walks you through configuring SAML-based Single Sign-On so your team members can authenticate with your organization’s identity provider instead of managing separate passwords.
This feature requires administrator or workspace owner permissions. Changes made here affect all users in your workspace.
Who should read this: Workspace administrators and account owners who manage authentication for their organization.Prerequisites: Admin or Account Owner role. An active identity provider (Okta, Azure AD, or Google Workspace) with admin access to create SAML applications. SSO must be enabled for your workspace (contact support if the SSO option is not visible).

Why Use SSO

Single Sign-On provides several benefits for aviation operations:
  • Centralized access control — onboard and offboard crew members through your existing identity provider.
  • Stronger security — enforce your organization’s password policies, MFA requirements, and conditional access rules at the IdP level.
  • Reduced credential fatigue — pilots and dispatchers use one set of credentials for all tools, reducing the risk of weak or reused passwords.
  • Compliance alignment — centralized authentication supports the access control requirements implicit in 14 CFR Part 5 safety data protection.

Before You Begin

Gather the following information from PlaneConnection before configuring your identity provider:
  1. Navigate to Settings > Security > Single Sign-On in your workspace.
  2. Copy the following values displayed on the SSO configuration page:
Do not share ACS URLs or Entity IDs publicly. These are specific to your workspace and are required for secure SAML assertion exchange.

Configure Your Identity Provider

Complete SSO Setup in PlaneConnection

Start with SSO optional during initial rollout. This lets you verify that all users can authenticate successfully before enforcing SSO-only access. Switch to SSO required once you have confirmed all team members can sign in.

Verify User Provisioning

After enabling SSO, users who sign in through your identity provider for the first time are automatically provisioned in PlaneConnection. Verify the following:
  1. The user appears on the Settings > Members page.
  2. Their email address matches the one from your identity provider.
  3. Their role defaults to Staff — assign the correct operational role (pilot, safety manager, dispatcher, etc.) after they sign in.
Auto-provisioned users receive the Staff role by default. You must manually assign the correct role for each user after their first SSO sign-in, or pre-create user accounts with the correct roles before enabling SSO. Incorrect role assignments can result in unauthorized access to safety-sensitive data.

Troubleshooting SSO

Verify that the ACS URL and Entity ID in your identity provider exactly match the values shown in PlaneConnection. Trailing slashes and case differences cause validation failures.
The email address from your identity provider must match the email address in PlaneConnection. Check that the Name ID attribute is set to the user’s email address in your IdP configuration.
New SSO users are provisioned with the Staff role by default. Navigate to Settings > Members and assign the correct role. See Manage Users and Roles.
If SSO is set to required and your identity provider is down, admins can sign in at https://app.planeconnection.com/sign-in?bypass_sso=true using their email and password (if they previously set one). This bypass is only available for users with the Admin or Account Owner role.

Manage Security Settings

Configure 2FA, passkeys, and session policies alongside SSO.

Manage Users and Roles

Assign roles to SSO-provisioned users.

User Roles Reference

All 24 platform roles and their capabilities.

Permissions Matrix

Full feature-by-role permissions breakdown.
Last modified on April 11, 2026