Onboard users
Getting your organization into Mattermost: connect the identity provider your users already have, and get their accounts in.
Access control for a workspace that's already running, including permissions and roles, is covered in access control.
Authentication
- Single sign-on - Connect Mattermost to your identity provider using SAML, OpenID Connect, or OAuth 2.0.
- AD/LDAP - Synchronize accounts and groups from Active Directory or LDAP.
- Multi-factor authentication - Require a second factor at sign-in.
- SSL client certificate setup - Configure mutual TLS authentication for browsers and the desktop apps.
Accounts
- Provisioning workflows - Choose how accounts are created, updated, and deactivated.
- Guest accounts - Give people outside your organization access to specific channels.
To pre-provision accounts in bulk, to bring teams, channels, and message history in from another system, or to move an existing deployment onto different infrastructure, see Migrate.