Articles on: Settings & Configuration

How to Migrate Users to SAML Authentication

How to Migrate Users to SAML Authentication


In this article:

  • Overview
  • Before you start
  • How to migrate users to SAML
  • Things to keep in mind
  • FAQs
  • Who can do this


Overview

Once SAML single sign-on is connected, you can move your existing people over to it in one step. The Migrate Users action in the Custom SSO section switches every person whose email matches your SSO email domain to SAML authentication, so they sign in through your identity provider from then on. This is a one-way change, so it's designed to be run deliberately after you've tested SSO with a few people first.


Before you start

  • SAML must already be configured for your account — the connection details, provider and SSO email domain all need to be set up. If they aren't, the migration won't run.
  • Test the SSO sign-in flow with a small number of people before migrating everyone. The migration cannot be reversed.


How to migrate users to SAML

  1. Go to Settings → Security.
  2. In the Custom SSO section, click Migrate Users.
  3. A Confirm SSO Migration dialog appears, explaining that all users with the specified SSO email domain will be moved to SAML authentication, that they'll no longer be able to sign in with their old method, and that the process cannot be reversed.
  4. Read the warning, then click Proceed to run the migration, or Cancel to back out.


When it finishes, you'll see a confirmation that your users were migrated. Anyone whose email matches the SSO domain will sign in through SAML on their next visit.


Things to keep in mind

  • Only people whose email address matches your configured SSO email domain are migrated. People on other domains are left unchanged and can still be invited or sign in as before.
  • Anyone already using SAML is skipped, so it's safe if some people are already on SSO.
  • After migration, affected people can no longer sign in with their previous method (such as email/password) — they must use SSO.
  • The migration cannot be reversed from the app, so test with a few people before running it for everyone.
  • Behind the scenes, each affected person's old sign-in identity is removed and re-created automatically the first time they sign in through SSO — so they simply sign in via your identity provider next time.


FAQs

Which people get migrated?
Everyone whose email address matches the SSO email domain configured for your SAML connection. People on other email domains are not affected.


What happens to people who are already on SAML?
They're skipped. The migration only changes people who are still on another sign-in method.


Can I undo the migration?
No. The confirmation dialog states the process cannot be reversed, which is why testing SSO with a small group first is strongly recommended.


What if some people don't get migrated?
Only matching-domain users are migrated, and anyone already on SAML is skipped. People on a different email domain keep their existing sign-in method.


Who can do this

Only Owners (and Super Admins) can migrate users to SAML — the Security settings tab and the SAML actions are restricted to Owners. Admins, Managers, Content Managers, People Managers, Instructors, Employees and Restricted users cannot.

Updated on: 17/07/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!