Go back

What SAML actually fixes: IT blocking a tool because it does not support enterprise login

A team spends real time evaluating a video tool, gets excited about it, starts building a case for adoption, and then hits a wall: IT and Cybersecurity blocks it, not because of anything wrong with the tool’s content generation quality, but because it doesn’t support SAML, the standard that lets the organization’s identity provider manage authentication. From the requesting team’s perspective, this can feel like an arbitrary bureaucratic obstacle standing between them and a tool they’ve already decided is worth using. It isn’t arbitrary. It’s one of the most consistent, legitimate requirements a security review applies, and understanding why helps both sides navigate the situation more productively.

Why this is a legitimate requirement, not an obstacle

SAML support determines whether a tool’s authentication can be governed the same way every other tool in the organization’s identity infrastructure is governed: centrally managed, subject to the same password policies, covered by multi-factor authentication requirements, and automatically deactivated the moment someone’s central access is revoked. A tool without SAML support requires its own separate, standalone login, which sits entirely outside that centrally managed system. This isn’t a minor technical gap, it’s the exact mechanism that creates the standalone-credential risk discussed elsewhere: access that can persist after someone leaves, that isn’t covered by centralized password and multi-factor policy, and that IT and Cybersecurity has no unified way to monitor or revoke alongside everything else.

This becomes concrete the moment it actually matters: an employee offboarding where every other tool’s access gets revoked automatically except this one, a security incident requiring a rapid, organization-wide credential reset that this tool sits outside of, an audit specifically checking which tools are integrated with the identity provider and which aren’t.

What real SAML support actually needs to provide

Genuine SAML 2.0 protocol support, not a proprietary workaround. The standard itself matters because it’s what lets a tool integrate reliably with whatever identity provider an organization already uses, Okta, Microsoft Entra, Google Workspace, rather than requiring a custom, less-tested integration built specifically for one platform.

Authentication that’s actually required, not just available. A tool that offers SAML as an option while still allowing a standalone password login path hasn’t fully closed the gap SAML is meant to address, since anyone using the standalone path remains outside centralized governance.

Provisioning and deprovisioning that follows identity changes automatically. When someone’s central identity is deactivated, their access to the SAML-integrated tool should be revoked automatically as part of that same event, not as a separate, manual step someone has to remember.

Reliable behavior during identity provider changes. Since organizations occasionally change or reconfigure their identity provider, a tool’s SAML integration needs to handle that kind of transition without breaking access or requiring a disruptive reconfiguration.

Velo supports this directly, letting organizations authenticate users through their identity provider using the SAML 2.0 standard, so a video tool’s access is governed through the same infrastructure as everything else, rather than sitting as an exception IT has to track separately.

SAML and SSO are often discussed together, and for good reason: SAML is the specific technical standard that makes a particular flavor of single sign-on possible, letting an identity provider authenticate a user to a third-party application. It’s worth understanding that “supports SSO” and “supports SAML” aren’t always exactly synonymous, some tools offer a form of single sign-on through a different, less standardized mechanism, which may not integrate as cleanly or reliably with every identity provider an organization might use. When a security review specifically asks for SAML, it’s asking for the widely adopted, well-tested standard, not just any authentication convenience that happens to reduce the number of passwords someone has to remember.

Why this requirement tends to surface late in an evaluation, not early

A team evaluating a new tool typically starts with the content or functionality that excited them about it in the first place, not with a technical authentication standard. This means SAML support often doesn’t get checked until relatively late in the evaluation process, sometimes not until a security review is already underway, by which point the team may have already invested significant time building enthusiasm and internal buy-in around a tool that then gets blocked. Checking SAML support as one of the very first steps in any enterprise tool evaluation, rather than as a late-stage formality, avoids this specific, entirely avoidable source of wasted effort and frustration.

What this looks like in practice

Consider a team that’s evaluated two otherwise comparable video tools, one supporting SAML, one not. The tool without SAML might look identical in terms of content generation quality, and the team advocating for it may not fully understand why IT is applying what feels like an arbitrary standard. But the practical difference shows up the moment someone using that tool leaves the company: with SAML, their access is revoked automatically as part of standard offboarding. Without it, their access persists on a standalone credential until someone specifically remembers this particular tool exists and manually revokes it, a step that, as with any manual process, gets missed with some regularity.

For IT and Cybersecurity, SAML support isn’t a preference, it’s the specific mechanism that determines whether a tool’s access can be governed with the same rigor as everything else, which is exactly why it tends to be treated as a hard requirement rather than a nice-to-have during security review.

What to check before assuming SAML support closes the gap

Is SAML actually required, or optional alongside a standalone login? Confirm whether the standalone login path can be fully disabled, since its continued availability undermines the point of requiring SAML in the first place.

Does deprovisioning happen automatically? Test this directly: deactivate a test identity and confirm the tool’s access is revoked without a separate manual step.

Is the SAML integration well-tested against your specific identity provider? Confirm compatibility with the exact system in use, rather than a generic SAML 2.0 claim, since real-world implementation quality can still vary.

A tool IT blocks over missing SAML isn’t being difficult, it’s doing its job

SAML support isn’t a bureaucratic checkbox, it’s the mechanism that lets a tool’s access be governed the same way as everything else an organization depends on. Confirm it’s genuinely required and properly implemented before a rollout depends on a tool that IT will eventually have to block.

Try Velo for free · See how it works


About the author

Ritu Parakh is Growth Lead at Velo, the AI video messaging platform that turns a screen recording, a deck, or a URL into a polished, narrated video - and an editable written doc. She writes about video for demos, onboarding, training, and enablement. Connect on LinkedIn

SAML support lets IT and Cybersecurity approve a tool with confidence that access flows through the organization's existing identity provider, rather than creating a separate authentication system outside normal policy.

SAML support means Knowledge Management can advocate for a tool without it being blocked at the security review stage over a missing enterprise login requirement that a competing tool already satisfies.

Configure the video platform's SAML integration against the organization's identity provider, test authentication with a pilot group, and confirm access provisioning and deprovisioning behave as expected before full rollout.

Confirm with IT and Cybersecurity that a prospective video tool supports SAML before investing significant evaluation time, since this requirement often determines whether a tool clears security review at all.

Bring the video layer to your product team