Skip to main content

Whitelist and blacklist SSO groups for site access

Allow or block specific SSO groups from accessing a Zoomforth site. Step-by-step SAML setup with notes on MFA and enterprise security.

Written by Troy Villasanta
Updated today

The primary role of Single Sign-On or Security Assertion Markup Language (SAML) in online security is that it enables you to access multiple web applications using one set of login credentials.

To enable Single Sign-On (SAML) authentication, your account admin will need to request this feature by contacting support@zoomforth.com.

Once SAML integration is enabled, the Single Sign-On (SAML) access setting can be used, as seen in the screenshot below:

Single sign-on settings

We have three Single Sign-On settings that you can use on your sites if Single Sign-On (SAML) has been activated for your account.

1. Allow all members of the Single Sign-On system to access the site.

Anyone who is a member of the Single Sign-On system or Identity Provider can access or log in to the site.

2. Only allow Single Sign-On members with specific emails to access the site.

Only visitors whose Single Sign-On email address has been added will be whitelisted and granted access to the site. The site owner should add specific email addresses to the given field. These specific email addresses should be members of the Single Sign-On system or Identity Provider in order to access or log into the site.

3. Only allow Single Sign-On members in specific groups to access the site.

Only visitors whose Single Sign-On group matches an approved group can access the site. The site owner should select the group from the registered Single Sign-On Groups. Multiple groups can be selected.


This article covers SSO group-level access control. For a broader overview of Zoomforth's enterprise security capabilities, including MFA and audit logs, visit the security features page.

Did this answer your question?