SSO
Available for Team and Enterprise plans. It ties Claude login to the customer's identity provider after domain verification.
A buyer-friendly guide to Claude SSO, domain verification, JIT provisioning, SCIM directory sync, group mapping, and Team versus Enterprise identity choices.
Available for Team and Enterprise plans. It ties Claude login to the customer's identity provider after domain verification.
Available for Team and Enterprise plans. It provisions users when they log in through the IdP.
Enterprise-only for Claude plans. It syncs users and groups from the IdP for stronger lifecycle control.
The right identity setup depends on how much lifecycle control the customer needs on day one. BlueSky keeps the decision explicit so Team customers do not wait for Enterprise-only features and Enterprise customers do not launch without access controls.
Best when speed matters and the team is small enough for manual member management.
Best when the customer wants IdP login control without full SCIM lifecycle automation.
Best for Enterprise programs that need automatic provisioning, deprovisioning, and group-based administration.
Identity work should leave behind proof that the setup is ready. That proof helps security reviewers, customer admins, and BlueSky operators avoid repeating the same discovery.
Capture DNS ownership and Claude domain verification status before SSO changes are enforced.
Record successful admin and pilot-user test logins before expanding beyond the initial group.
For JIT or SCIM, document which groups are assigned, which users appear in Claude, and who owns rollback.
These are the decisions BlueSky wants settled before a rollout becomes harder than it needs to be.
No. Anthropic documents SCIM directory sync for Enterprise plans and eligible Console organizations. Claude Team can use invite-only or JIT provisioning.
Domain verification proves ownership of the email domain and is required before Claude can safely bind sign-in behavior to the customer's identity provider.
A common issue is mismatched identity attributes. The email claim used for SSO should align with the email attribute used for provisioning.
Official Claude documentation remains the source of truth for current plan capabilities and setup screens.