Skip to main content
SAML single sign-on lets your team sign in to Great Question with your existing Microsoft Entra ID (Azure AD) credentials. This guide walks through creating the enterprise application in Azure AD and connecting it to Great Question.
SAML authentication is available on Enterprise plans only. Each Great Question account supports a single SAML provider at a time, if you need Okta instead, see the Okta SAML guide; setting one up replaces the other.

Step 1: Create the enterprise application in Azure AD

  1. In Azure AD, create a new enterprise application and set up Single Sign-On with SAML.
  2. Configure the following identifiers:
  1. From the Azure AD SAML configuration, gather these three items:
    • The Base64 certificate (download it)
    • The Azure AD Identifier
    • The Login URL

Step 2: Connect Azure AD in Great Question

  1. In Great Question, go to Settings > Governance > Security.
  2. Under Authentication methods, enable SAML.
  3. Click Setup next to SAML configuration and enter the values you gathered from Azure AD:
Paste the certificate exactly as downloaded, including the -----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- lines and all line breaks. Extra whitespace or missing header lines are the most common cause of a failed connection.

Signing in

Once SAML is configured, any user with access to Great Question in your Azure AD can sign in directly from their Azure AD profile. A first-time sign-in with no pending invite defaults to a free Observer account. Existing Great Question users can connect their Azure AD login by going to greatquestion.co/sso and entering their work email.
Still need help? Contact us at support@greatquestion.co — median response time is 19 minutes during support hours.