Skip to main content
GitHub Docs
Version:
Enterprise Cloud
Search GitHub Docs
Search
Select language: current language is English
Open Search Bar
Close Search Bar
Open Menu
Open Sidebar
Enterprise administrators
/
Identity and access management
Home
Enterprise administrators
Overview
About GitHub for enterprises
About GitHub Enterprise Cloud
Enterprise Cloud trial
Feature overview
Enterprise Server trial
Best practices
Access compliance reports
Data residency
What is data residency?
How is data stored?
Which features are available?
Get started
Network details
Resolving issues
Manage enterprise account
About enterprise accounts
Create enterprise account
Create a README
Delete enterprise account
Change enterprise URL
Create a GitHub App
Configuration
Configure user applications
Verify or approve a domain
Harden security
Restricting network traffic
Hosted compute networking
About hosted compute networking
About Azure private networking
Configuring private networking
Troubleshooting Azure private networking
Identity and access management
Understand enterprise IAM
About IAM
About SAML for IAM
About managed users
Restrictions for managed users
Choosing an enterprise type
Get started with managed users
Troubleshoot IAM
IAM configuration reference
SAML reference
Username considerations
SAML for enterprise IAM
Enterprise or organization
Configure SAML SSO
Manage team synchronization
Configure SAML SSO with Okta
Disable SAML SSO
From organization to enterprise
Troubleshoot SAML SSO
Authentication for managed users
Configure SAML
Configure OIDC
Configure SAML on Okta
Find ID for Entra OIDC
Conditional access policy
Disable authentication and provisioning
Provision managed user accounts
Configure SCIM provisioning
Set up PingFederate
Set up Okta
SCIM using REST API
Manage teams with your IdP
Troubleshoot team membership with IdP
Reconfigure IAM for managed users
Migrate to new IdP or tenant
Migrate from OIDC to SAML
Migrate from SAML to OIDC
Manage recovery codes
Download recovery codes
Access your enterprise account
Manage accounts and repositories
Communicate info to users
Customizing user messages
Configure custom footers
Manage users
Roles in an enterprise
Invite people to manage
Manage organization invitations
Managing organization members
Manage support entitlements
View people in your enterprise
Export membership information
View & manage SAML access
Remove member
Managing dormant users
Enabling guest collaborators
Manage organizations
Best practices
Add organizations
Manage your organization roles
Manage requests for Copilot
Remove organizations
Manage repositories
View user-owned repositories
Access user-owned repositories
Policies
Enforce policies
About enterprise policies
Repository management policies
Projects policies
Restrict email notifications
GitHub Sponsors policies
Policies for security settings
GitHub Actions policies
GitHub Copilot policies
GitHub Codespaces policies
Code security & analysis
Personal access token policies
Monitor user activity
Review audit logs
About audit logs
Access audit logs
IP addresses in audit log
Search audit logs
Identify events by token
Export audit logs
Stream audit logs
Audit log API
Audit log events
Explore user activity
Manage global webhooks
GitHub Actions
Get started
About GitHub Actions
Introduce Actions
Migrate to Actions
Get started
Self-hosted runners
Code security
GitHub Advanced Security
Manage GitHub Advanced Security
Configuring code scanning
Copilot Business only
About the account
Set up with personal accounts
Set up with managed users
Guides
Enterprise administrators
/
Identity and access management
Identity and access management
You can configure how people access your enterprise on GitHub Enterprise Cloud.
Understanding IAM for enterprises
About identity and access management
About SAML for enterprise IAM
About Enterprise Managed Users
Abilities and restrictions of managed user accounts
Choosing an enterprise type for GitHub Enterprise Cloud
Getting started with Enterprise Managed Users
Troubleshooting identity and access management for your enterprise
IAM configuration reference
SAML configuration reference
Username considerations for external authentication
Using SAML for enterprise IAM
Deciding whether to configure SAML for your enterprise or your organizations
Configuring SAML single sign-on for your enterprise
Managing team synchronization for organizations in your enterprise
Configuring SAML single sign-on for your enterprise using Okta
Disabling SAML single sign-on for your enterprise
Switching your SAML configuration from an organization to an enterprise account
Troubleshooting SAML authentication
Configuring authentication for Enterprise Managed Users
Configuring SAML single sign-on for Enterprise Managed Users
Configuring OIDC for Enterprise Managed Users
Configuring SAML single sign-on with Okta for Enterprise Managed Users
Finding the object ID for your Entra OIDC application
About support for your IdP's Conditional Access Policy
Disabling authentication and provisioning for Enterprise Managed Users
Provisioning accounts for Enterprise Managed Users
Configuring SCIM provisioning for Enterprise Managed Users
Configuring authentication and provisioning with PingFederate
Configuring SCIM provisioning with Okta
Provisioning users and groups with SCIM using the REST API
Managing team memberships with identity provider groups
Troubleshooting team membership with identity provider groups
Reconfiguring IAM for Enterprise Managed Users
Migrating your enterprise to a new identity provider or tenant
Migrating from OIDC to SAML
Migrating from SAML to OIDC
Managing recovery codes for your enterprise
Downloading your enterprise account's single sign-on recovery codes
Accessing your enterprise account if your identity provider is unavailable