Sign in and SSO
How users authenticate to Surfaice and what administrators configure for SSO and MFA.
Surfaice authentication is handled through your company's identity provider.
End users
- Visit agent.surfaice.pro.
- Choose your organization's sign-in method when prompted.
- Complete any MFA challenge required by your identity provider.
If sign-in fails, try your corporate SSO portal first, then retry Surfaice. Persistent failures usually mean your account has not been provisioned into a Surfaice workspace yet — ask your Surfaice administrator.
Administrators
Surfaice supports single sign-on with providers such as:
- Microsoft Entra ID (Azure AD)
- Google Workspace
- Other SAML / OIDC providers (as configured for your tenant)
Multi-factor authentication is supported and can be enforced at the tenant level through your IdP policies.
Role-based access inside Surfaice controls:
- Which data scopes a user can reach
- Which connectors a role is allowed to use
