SAML authentication is available on Enterprise plans only. Each Great Question account supports a single SAML provider at a time, if you need Azure AD instead, see the Azure AD SAML guide; setting one up replaces the other. Other providers, such as Google Workspace, OneLogin, and JumpCloud, use the same ACS URL, Entity ID, Name ID format, and attribute names shown in Step 1, mapped to the matching user fields in that provider.
Step 1: Create the application in Okta
- In the Okta admin console, create a new SAML 2.0 application.
- Configure the following URLs:
- Set Name ID format to
EmailAddressand Application username toEmail. - Map these attributes:
Step 2: Connect Okta in Great Question
- In Great Question, go to Settings > Governance > Security.
- Under Authentication methods, enable SAML.
- Click Setup next to SAML configuration and enter the three values from Okta’s setup instructions:
- Identity Provider Single Sign-On URL
- Identity Provider Issuer
- X.509 Certificate
Signing in
Once SAML is configured, any user with access to Great Question in Okta can sign in directly from their Okta profile. A first-time sign-in with no pending invite defaults to a free Observer account. Existing Great Question users can connect their Okta login by going to greatquestion.co/sso and entering their work email.Still need help? Contact us at support@greatquestion.co — median response time is 19 minutes during support hours.