Single Sign-On

Single Sign-On is a DefectDojo Pro feature. As of DefectDojo 3.0, the SSO surface — SAML, OIDC, and the bundled OAuth providers — is available only in DefectDojo Pro. Open-source DefectDojo uses local username/password login and the password-reset flow.

If you’re running open-source DefectDojo and want SSO, you’ll need to switch to DefectDojo Pro; the migration is covered in the 3.0 upgrade notes. Existing user accounts and group memberships are preserved on upgrade. For access control on open-source DefectDojo, see the Authorized Users page.

How SSO configuration works

Two things are worth understanding before you set up a provider:

  • Where settings live. Almost every provider is configured under Connect > Authorization > Providers in the Pro UI (SAML, OIDC, the OAuth providers, LDAP, SCIM). Those values are saved in DefectDojo and take effect immediately — no restart. Two providers are the exception: Remote User (Header) Authentication is configured with environment variables only, and on-premise installs may also set any provider’s boot-time defaults through environment variables. Where both exist, the value saved in the DefectDojo UI wins at runtime — the environment variable is only the starting default.
  • Configured vs enabled. Filling in a provider’s form does not switch it on. Each provider has its own Enable checkbox; the login button (or, for LDAP, the credential check) only appears once the provider is both configured and enabled and the form is saved. Authorization Connectors shows both states on one page.

SSO, LDAP and SCIM are part of the DefectDojo Pro licensed feature set. If the provider tiles under Connect > Authorization > Providers are not visible, your subscription does not include them — contact DefectDojo Support.

Seeing what is configured

Authorization Connectors lists every supported provider on one page — which are configured, which are enabled, and what protocol each speaks — and takes you straight to the settings form for any of them. Start there if you want to know the state of this instance rather than set up a specific provider.

Supported SSO providers (DefectDojo Pro)

Each guide walks through the provider-side setup and the corresponding configuration in DefectDojo. The generic standards come first, then the branded OAuth providers, then the directory-backed methods.

Standards

OAuth 2.0 providers

Directory / proxy

Each provider’s page states the exact callback / redirect URI to register at your identity provider. You can also read it back from the provider’s own settings form using Validate Config, which echoes the value DefectDojo expects.

Provisioning users from your directory (DefectDojo Pro)

The providers above decide who may sign in. SCIM Provisioning keeps the account list itself in step with your directory, so users are created when they join, updated when their details change, and deactivated (along with their API tokens) when they leave.

SSO configuration in DefectDojo Pro can only be performed by a Superuser.

DefectDojo Pro users: Add the IP addresses of your SAML or SSO services to the Firewall whitelist before setting up SSO. See Firewall Rules for more information.

The login page itself

How the login page behaves once SSO is in place — disabling username/password login, auto-redirecting to your provider, session length, and just-in-time user creation — is covered on the Login Settings page.

If your SSO integration stops working, you can always return to the standard login form by appending ?force_login_form to your DefectDojo login URL. Keep at least one Superuser account with a username and password as a break-glass fallback.

Auth0 →

Configure Auth0 SSO in DefectDojo Pro

Authorization Connectors →

See every identity provider on one page: which are configured, which are enabled, and what protocol each one speaks

Azure Active Directory →

Configure Azure AD / Microsoft Entra ID SSO and group mapping in DefectDojo Pro

GitHub Enterprise →

Configure GitHub Enterprise SSO in DefectDojo Pro

GitLab →

Configure GitLab SSO in DefectDojo Pro

Google Auth →

Configure Google OAuth in DefectDojo Pro

KeyCloak →

Configure KeyCloak SSO in DefectDojo Pro

LDAP Authentication →

Configure LDAP authentication in DefectDojo Pro

Login Settings →

Control the DefectDojo login page: disable password login, auto-redirect to SSO, session length, and JIT user creation

OIDC →

Configure OpenID Connect (OIDC) SSO in DefectDojo Pro

Okta →

Configure Okta SSO in DefectDojo Pro

Remote User (Header) Authentication →

Authenticate users from a trusted reverse proxy via request headers in DefectDojo Pro

SAML Configuration →

Configure SAML in DefectDojo Pro

SCIM Provisioning →

Provision and deprovision DefectDojo Pro users from your identity provider