Change your single sign-on provider

Want to change your single sign-on (SSO) provider? This guide will help you make a seamless transition. Keep in mind that you'll need to set aside some time in order to complete the process in one go.

Tip: Org Owners on Enterprise plans can add up to 11 additional SSO configurations to use SSO with multiple identity providers (IDPs).


Change your SSO provider

Free, Pro, and Business+ plans

Enterprise plans

Step 1: Remove SSO configuration

  1. Click your workspace name in the sidebar.
  2. Hover over Tools & settings, then click Workspace settings.
  3. Below Administration in the left sidebar, click   SSO & authentication
  4. Click Disable SSO Config in the top-right corner of the page.
  5. Choose whether to send an email to your members to let them know SSO has been turned off, then click Disable SSO

Anyone already logged in to Slack when you disable SSO will remain logged in.


Step 2: Set up your new SSO configuration 

  1. Click your workspace name in the sidebar.
  2. Hover over Tools & settings, then click Workspace settings.
  3. Below Administration in the left sidebar, click SSO & authentication
  4. Next to An identity provider or custom SAML, click Configure SAML
  5. In the top right, toggle Test mode on. 
  6. Next to SAML SSO URL, enter your SAML 2.0 Endpoint URL (HTTP). (This came from setting up your connector earlier). If Okta is your IDP, you can include the IDP URL instead if you'd like.
  7. Next to Identity Provider Issuer, enter your IDP Entity ID.
  8. Copy the entire x.509 Certificate from your IDP and paste it into the Public Certificate field.
  9. Next to Advanced Options, click Expand. Choose how the SAML response from your IDP is signed. If you need an end-to-end encryption key, check the box next to SignAuthnRequest to show the certificate.
  10. Below Settings, decide if members can edit their profile information (like their email or display name) after SSO is enabled. You can also choose whether SSO is required, partially required, or optional.
  11. Below Customize, enter a sign-in button label.
  12. Click Save Configuration to finish.

Members will receive an email asking them to connect their existing Slack account with their profile in your updated IDP. Members need to click the SSO binding email within 72 hours, but admins can re-send these emails from the Manage members page.

  1. Click your organization name in the sidebar.
  2. Hover over Tools & settings, then click Organization settings.
  3. From the sidebar, click   Security, then click SSO Settings.
  4. Next to your current IDP, click Edit Configuration.
  5. Replace the SAML 2.0 Endpoint URL with the new value provided by your IDP when you set up the connector.
  6. Replace your Identity Provider Issuer URL.
  7. Replace the Service Provider Issuer URL if this has been set in your IDP. This value is set to https://slack.com by default.
  8. Copy the entire x.509 Certificate from your identity provider and paste it into the Public Certificate field.
  9. Choose whether the SAML responses and assertions are signed. You can also change your preference for AuthnContextClassRef values.
  10. Click Test Configuration. We'll let you know if the changes are successful or whether you need to make further changes.
  11. When you're ready, click Apply Changes.

Tip: If you have guests in your workspace or organization, we recommend choosing the option where SSO is partially required so they can still sign in with their email address and password.


Tips for changing over 

Here are a few things to keep in mind to ensure the change goes smoothly.

Who can use this feature?