Cargo Marshal
Dashboard
Cargo Marshal
Dashboard
Cargo Marshal Docs
Create your first Load PlanAxle loadsSingle sign-on with OktaSingle sign-on with Microsoft Entra IDSingle sign-on with Google WorkspaceSSO break-glass access
Guides

Single sign-on with Okta

Connect Okta to Cargo Marshal over SAML, verify your email domain, and let your team sign in with their Okta accounts.

Single sign-on with Google Workspace

Connect Google Workspace to Cargo Marshal as a custom SAML app, verify your email domain, and let your team sign in with their Google work accounts.

Guides

Single sign-on with Microsoft Entra ID

Connect Microsoft Entra ID (Azure AD) to Cargo Marshal over SAML, verify your email domain, and let your team sign in with their Microsoft work accounts.

Single sign-on (SSO) lets people with an email on your company domain sign in to Cargo Marshal through Microsoft Entra ID. Their first sign-in adds them to your organization as members, as long as a seat is free.

Before you start

You need the Enterprise plan, the owner or admin role in your Cargo Marshal organization, an Entra role that can create enterprise applications (for example Application Administrator), and access to your domain's DNS settings.

Connect Entra ID

Copy the Cargo Marshal values

In Cargo Marshal, open Settings → Single sign-on and keep SAML selected. Copy the ACS URL and the Entity ID.

Create the enterprise application

In the Microsoft Entra admin center, go to Enterprise applications → New application → Create your own application, name it "Cargo Marshal", and choose the non-gallery option. Open Single sign-on and choose SAML.

Enter the Cargo Marshal values

Edit Basic SAML Configuration:

  • Identifier (Entity ID): the Entity ID from Cargo Marshal.
  • Reply URL (Assertion Consumer Service URL): the ACS URL from Cargo Marshal.

Edit Attributes & Claims and set the Unique User Identifier (Name ID) to user.mail with the format Email address, so Cargo Marshal receives the work email. Keep Sign SAML assertion in the signing options; Cargo Marshal rejects unsigned assertions.

Copy the Entra values

In SAML Certificates, download Certificate (Base64). In the Set up Cargo Marshal section, copy the Login URL and the Microsoft Entra Identifier.

Connect in Cargo Marshal

Back in Settings → Single sign-on, enter your email domain (for example acme.com). Paste the Login URL into IdP single sign-on URL, the Microsoft Entra Identifier into IdP entity ID (issuer), and the certificate file's contents into IdP signing certificate. Click Connect.

Verify your domain

Cargo Marshal shows a TXT record. Add it at your DNS provider, then click Verify domain. DNS changes can take a while to appear. Sign-in through SSO starts working once the domain is verified.

Assign people and sign in

In Users and groups, assign the people or groups who use Cargo Marshal. They sign in at the Cargo Marshal login page with Sign in with SSO and their work email.

Entra ID also supports OpenID Connect. To use it instead, select OpenID Connect in Cargo Marshal, register a web app under App registrations with the Redirect URI, create a client secret, and enter https://login.microsoftonline.com/<tenant-id>/v2.0 as the issuer with the app's client ID and secret.

Require SSO

Once the domain is verified and you have signed in through SSO yourself, you can turn on Require SSO. Everyone on the domain is signed out, except you, and can then only sign in through Entra ID. If Entra ID is ever unavailable, see SSO break-glass access.

Troubleshooting

  • "Single sign-on isn't set up for this email domain": the domain is not verified yet, or the email is on a different domain.
  • "Your organization has no free seat": the plan's member limit is reached. Free a seat or invite the person, then sign in again. An invited person can always join.
  • "…an email outside your organization's verified domain": Entra sent a different email than the one on your domain, often the user principal name. Set the Name ID to user.mail.

Single sign-on with Okta

Connect Okta to Cargo Marshal over SAML, verify your email domain, and let your team sign in with their Okta accounts.

Single sign-on with Google Workspace

Connect Google Workspace to Cargo Marshal as a custom SAML app, verify your email domain, and let your team sign in with their Google work accounts.

On this page

Connect Entra IDCopy the Cargo Marshal valuesCreate the enterprise applicationEnter the Cargo Marshal valuesCopy the Entra valuesConnect in Cargo MarshalVerify your domainAssign people and sign inRequire SSOTroubleshooting