1. Home
  2. Applications
  3. Claude AI
  4. Enable SSO for Claude AI

Enable SSO for Claude AI

Purpose

Claude AI offers single sign-on via SAML integration with Practice Protect. This provides a seamless login experience to the Claude AI platform using IdP-initiated SSO.

Practice Protect will configure this on your behalf. Please send us an email at support@practiceprotect.com

Prerequisites

  • Claude requires any of these subscriptions (Team plans, Enterprise plans, and Console organizations) to enable SSO integration. For Team or Enterprise plans: You must be an Owner or Primary Owner. For Claude Console: You must be an Admin.
  • Admin Access to Practice Protect
  • Claude Username/Email for staff should match the login names in Practice Protect.
  • Your domain must be verified in Claude, otherwise SSO will not be available. To learn more, visit the relevant documentation page.

Setup & Enable Single Sign-On
  1. To get started, sign in to Claude and click your profile icon in the bottom-left corner, then select Organization Settings.

    Alternatively, you can go directly to: Claude Organization Settings

  2. Under Organization & Access, navigate to the Authentication section, then click Setup SSO to configure Single Sign-On.
  3. This will open a new page in your browser for the SSO configuration.
  4. Locate and select CyberArk SAML as the Identity Provider.
  5. This will open the instructional setup page, which we will follow throughout the SSO configuration process. As outlined in the first step, begin by creating a SAML App.

  6. Next step is sign in to Practice Protect and switch to the Admin Portal. It’s recommended to open a new tab for this while keeping the Claude SSO configuration page open, so you can work through both setups simultaneously
  7. Follow the instructions to navigate to Apps & Widgets > Web Apps, then click Add Application
  8. Select the Custom tab, then click Add next to SAML
  9. Click Yes.
  10. Set the Name of the app to Claude SSO
  11. Click Browse to upload a logo. You can use and download the below icon.
  12. Click Save.


  13. Return to the Create a SAML App page in Claude SSO Configuration.

  14. Copy both the SP Entity ID and the Assertion Consumer Service (ACS) URL values, as these will be required for the SAML application setup.

  15. Return to the Claude application in the Practice Protect Admin Portal and proceed to the Trust tab.

  16. Scroll down to Service Provider Configuration and follow the configuration below:

    • Select Manual Configuration
    • Paste the SP Entity ID into the corresponding field
    • Paste the Assertion Consumer Service (ACS) URL into the corresponding field
    • Ensure Same as ACS URL is ticked
    • For Sign Response or Assertion?, select Both

    The rest of the settings can be left as default. Once completed, click Save.

  17. Return to the Create a SAML App page in Claude and click Continue to proceed to the next step, Configure SAML Attributes.
  18. To configure the SAML Attributes, return to the Claude SSO application in the Practice Protect Admin Portal and navigate to the SAML Response section.

  19. To add an attribute, click Add. Then, add the attributes listed below:

    • Attribute Name: id – Attribute Value: LoginUser.Uuid
    • Attribute Name: email – Attribute Value: LoginUser.Email
    • Attribute Name: firstName – Attribute Value: LoginUser.FirstName
    • Attribute Name: lastName – Attribute Value: LoginUser.LastName
    • Attribute Name: groups – Attribute Value: LoginUser.GroupNames
  20. Click Save.
  21. Return to the Configure SAML Attributes page in Claude and click Continue to proceed to the next step, Add Users to the SAML app.
  22. Proceed to Step 3: Add Users to the SAML App. In the Practice Protect Admin Portal, go to Core Services and navigate to Roles, then click Add Role.

  23. Create a new role named Claude SSO Users, then click Save.

  24. With the newly created role selected, go to Members and click Add. Add the users who should have access to the application, then click Save.
  25. Once added, go to Apps & Widgets > Web Apps > Select the Claude SSO app.
  26. Navigate to Permissions and click Add.
  27. Select the role you created earlier (e.g. Claude SSO Users), then click Add and Save
  28. Once completed, return to the Add Users to the SAML App page in Claude and click Continue to proceed to the next step, Set Identity Provider Metadata.

  29. In Step 4: Set Identity Provider Metadata, select Dynamic Configuration, then we follow the instructions provided on the page.
  30. Go back to the Claude SSO application in the Practice Protect Admin Portal via Apps & Widgets > Web Apps > Claude SSO, then navigate to the Trust tab.

  31. Under Identity Provider Configuration, select Metadata and click Copy URL. This is the Metadata URL required for the Claude SSO configuration.

  32. Click Save, then return to the Claude SSO page in your browser under Step 4: Set Identity Provider Metadata.
  33. As instructed on the page, paste the copied Metadata URL into the Identity Provider Metadata URL field.
  34. Click Continue to proceed to the next step
  35. As part of the final step, Step 5: Test Single Sign-On, click Continue to sign-in to proceed with the sign-in test.
  36. This will redirect you to Practice Protect to sign in. The user must use their Practice Protect credentials to verify the connection and complete the testing. This is the final step required to complete the SSO setup.
  37. Once successful, a message stating “Connection activated” will appear. You can now close the page.

  38. SSO is now enabled. Users can also access the Claude SSO app directly through the Practice Protect portal.

    It is recommended to test SSO with the remaining users to ensure it is working correctly across all platforms, including browser, desktop, and mobile versions.


    Take note that at this stage, users still have the option to either  sign in using their regular credentials or via the SSO.

  39. To enforce SSO, navigate back to Claude Organization Settings > Authentication.

  40. Switch on the option Require SSO for Claude. Once enabled, regular users will only be able to sign in to Claude through SSO.

  41. SSO configuration is now complete.

Updated on May 21, 2026
Need Support?
Can't find the answer you're looking for?
Contact Support