Hi all,
We're excited to share that tenant admins can now configure SAML-based single sign-on directly in the Tenant Admin Console, without going through Benchling Support.
What you can do:
- Add, edit, disable, and delete SAML authentication options for your tenant
- Provide IdP metadata via URL or file upload
- Configure SAML for customer domains or for all users
Built-in test flow
Before any new SAML configuration can be saved, you'll complete a test that validates the connection end-to-end. If the person configuring SAML doesn't have an email on the target domain, they can copy a shareable test link and send it to someone who does. This catches misconfiguration before it affects any users.
Lockout prevention
The console prevents you from removing or disabling the last authentication option that would leave users without a way to sign in. You also can't disable the option you're currently logged in with, so you won't accidentally lock yourself out.
For details on how to configure SAML in the Tenant Admin Console, check out our Help Center article.
We welcome any feedback as you start using this. Let us know how it goes in the comments below.

