> ## Documentation Index
> Fetch the complete documentation index at: https://docs.surfaice.pro/llms.txt
> Use this file to discover all available pages before exploring further.

# Sign in and SSO

> How users authenticate to Surfaice and what administrators configure for SSO and MFA.

Surfaice authentication is handled through your company's identity provider.

## End users

1. Visit [agent.surfaice.pro](https://agent.surfaice.pro).
2. Choose your organization's sign-in method when prompted.
3. Complete any MFA challenge required by your identity provider.

If sign-in fails, try your corporate SSO portal first, then retry Surfaice. Persistent failures usually mean your account has not been provisioned into a Surfaice workspace yet — ask your Surfaice administrator.

## Administrators

Surfaice supports single sign-on with providers such as:

* Microsoft Entra ID (Azure AD)
* Google Workspace
* Other SAML / OIDC providers (as configured for your tenant)

Multi-factor authentication is supported and can be enforced at the tenant level through your IdP policies.

Role-based access inside Surfaice controls:

* Which data scopes a user can reach
* Which connectors a role is allowed to use

## Related

* [Permissions model](/concepts/permissions)
* [Support](/support)
