Cargo Marshal
Dashboard
Cargo Marshal
Dashboard
Cargo Marshal Docs
Create your first Load PlanAxle loadsSingle sign-on with OktaSingle sign-on with Microsoft Entra IDSingle sign-on with Google WorkspaceSSO break-glass access
Guides

Single sign-on with Microsoft Entra ID

Connect Microsoft Entra ID (Azure AD) to Cargo Marshal over SAML, verify your email domain, and let your team sign in with their Microsoft work accounts.

SSO break-glass access

What happens when your identity provider is down while SSO is required, and how Cargo Marshal support restores access.

Guides

Single sign-on with Google Workspace

Connect Google Workspace to Cargo Marshal as a custom SAML app, verify your email domain, and let your team sign in with their Google work accounts.

Single sign-on (SSO) lets people with an email on your company domain sign in to Cargo Marshal through Google Workspace. Their first sign-in adds them to your organization as members, as long as a seat is free.

Before you start

You need the Enterprise plan, the owner or admin role in your Cargo Marshal organization, a Google Workspace super admin account, and access to your domain's DNS settings.

Connect Google Workspace

Copy the Cargo Marshal values

In Cargo Marshal, open Settings → Single sign-on and keep SAML selected. Copy the ACS URL and the Entity ID.

Create the custom SAML app

In the Google Admin console, go to Apps → Web and mobile apps → Add app → Add custom SAML app and name it "Cargo Marshal".

Copy the Google values

On Google Identity Provider details, copy the SSO URL and the Entity ID, and download the Certificate. Click Continue.

Enter the Cargo Marshal values

On Service provider details:

  • ACS URL: the ACS URL from Cargo Marshal.
  • Entity ID: the Entity ID from Cargo Marshal.
  • Name ID format: EMAIL.
  • Name ID: Basic Information → Primary email.

Click Continue, then Finish.

Connect in Cargo Marshal

Back in Settings → Single sign-on, enter your email domain (for example acme.com). Paste Google's SSO URL into IdP single sign-on URL, Google's Entity ID into IdP entity ID (issuer), and the certificate file's contents into IdP signing certificate. Click Connect.

Verify your domain

Cargo Marshal shows a TXT record. Add it at your DNS provider, then click Verify domain. DNS changes can take a while to appear. Sign-in through SSO starts working once the domain is verified.

Turn the app on and sign in

In the app's User access, turn it ON for everyone or for the organizational units that use Cargo Marshal. Changes can take a few minutes in Google. People then sign in at the Cargo Marshal login page with Sign in with SSO and their work email.

Require SSO

Once the domain is verified and you have signed in through SSO yourself, you can turn on Require SSO. Everyone on the domain is signed out, except you, and can then only sign in through Google Workspace. Signing in with the Google button on the login page also stops working for them. If Google Workspace is ever unavailable, see SSO break-glass access.

Troubleshooting

  • "Single sign-on isn't set up for this email domain": the domain is not verified yet, or the email is on a different domain.
  • "Your organization has no free seat": the plan's member limit is reached. Free a seat or invite the person, then sign in again. An invited person can always join.
  • "…an email outside your organization's verified domain": Google sent a different email than the one on your domain. Set the Name ID to the primary email.

Single sign-on with Microsoft Entra ID

Connect Microsoft Entra ID (Azure AD) to Cargo Marshal over SAML, verify your email domain, and let your team sign in with their Microsoft work accounts.

SSO break-glass access

What happens when your identity provider is down while SSO is required, and how Cargo Marshal support restores access.

On this page

Connect Google WorkspaceCopy the Cargo Marshal valuesCreate the custom SAML appCopy the Google valuesEnter the Cargo Marshal valuesConnect in Cargo MarshalVerify your domainTurn the app on and sign inRequire SSOTroubleshooting