Skip to content
English
  • There are no suggestions because the search field is empty.

Error: SSO Sign-in creates new organization

Changing your sign-in method from OIDC to SAML SSO requires sign-in using your SSO tenant and if not setup correctly, this may result in users not joining your organization

As an Organization Admin you may see a prompt to create a new organization instead of joining an existing one during SSO setup. In this instance, you may need to change your Identity Provider to properly connect to your organization account.

Please follow the steps below to ensure your sign-in completes using SSO:

  1. Sign in to the Admin Console with your original OIDC method (Apple, Google or Microsoft) and ensure auto-capture is enabled for your Domain.
  2. Sign out
  3. Sign in to the App via web (https://web.goodnotes.com) using SAML SSO.
  4. Click the "gear" icon in the top-right to open the settings menu, then click "Manage Account", then "Delete Account".
  5. Follow the steps to delete the account, including "Want to permanently delete your account immediately?" at the bottom of the screen and confirming.

    image_full delete.png
  6. Go back to the Admin Console (https://org-admin.goodnotes.com). Sign in with SAML SSO. This time the account should automatically join the organization. You should see the "No access" screen because your new SAML SSO user has the "Member" role.
  7. To promote your new SAML SSO user to "Organization Admin", sign out of the Admin Console, then sign in again using your original sign in method (Google/Apple/Microsoft). Go to "User Management" and find the row for your new SAML SSO account. Change the role to "Organization Admin".
  8. Finally, sign out of the Admin Console once more and sign in using SAML SSO.

You should now have access to the Admin Console using SAML SSO. You can delete the original account created by the initial sign-in (Google/Apple/Microsoft) from the Admin Console if you wish.

Please make sure to complete the "permanently delete your account" step at the end of the deletion process, as this step is easily missed.