Proton Pass for Business homepage

Plug Proton Pass into the stack you already use

Proton Pass works with the identity providers you already manage so you centralize access control without rebuilding your workflows.

Why you still need a password manager even with SSO

SSO covers the apps connected to your IdP. But your team uses dozens of tools that SSO doesn’t reach: legacy systems, shared team credentials, vendor portals, SaaS tools employees set up without IT involvement.

Proton Pass fills that gap. It governs the credentials SSO can’t touch — while giving IT visibility into what tools employees are actually using. Shadow IT becomes auditable. Credentials outside the SSO perimeter become manageable.

Your IdP handles authentication for covered apps. Proton Pass handles everything else — securely, centrally, and with the same audit trail.

Single sign-on (SSO)

Supported protocol: SAML 2.0

Proton Pass supports SAML 2.0 — the standard protocol your identity provider already speaks. Employees authenticate through your IdP. No separate Proton credentials to manage or reset.

Compatible identity providers

Confirmed supported IdPs:

  • Okta (SSO + SCIM)
  • Microsoft Entra ID / Azure AD (SSO + SCIM)
  • Google Workspace (SSO)
  • OneLogin (SSO)

Setup guides and documentation are available for each provider in the Proton Pass support center.

What SSO means for employees and for IT

For employees: one login for IdP-connected apps. No separate Proton credentials to remember, reset, or rotate.

For IT: authentication is centralized. Proton Pass accounts inherit the same session controls, 2FA policies, and access requirements as the rest of your stack. Password reset tickets for Pass accounts go to zero.

SCIM provisioning: automate your entire user lifecycle

SCIM connects your identity directory to Proton Pass. User lifecycle events in your IdP propagate automatically — no manual steps, no support tickets.

SCIM is confirmed for Okta and Microsoft Entra ID. Contact the team for provisioning options with other identity providers.

Onboarding a new employee

New hire added to your IdP → Proton Pass account created → assigned to the correct vault groups → ready to use. No IT ticket. No delay. No manual configuration per user.

Offboarding on departure — instant and complete

Employee deprovisioned in your IdP → Proton Pass access revoked immediately. No manual offboarding checklist. No window where a departing employee retains access to company credentials — including credentials for tools outside your SSO perimeter.

Scale: from 10 to 10,000 users

SCIM provisioning carries no manual overhead at scale. The same admin configuration that works for 10 users works for 10,000. Onboarding time does not grow with headcount.

Proton Pass is available on all major platforms and browsers, everywhere

Browser extensions

Chrome, Firefox, Safari, Edge, Brave — full autofill on all major browsers. Employees use the browser they already use.

Desktop and mobile apps

Windows, macOS, Linux, iOS, Android. The vault is accessible from every device your team uses.

Offline access

The vault remains accessible without an internet connection. Field teams, travellers, and remote workers are not blocked by connectivity gaps.

Audit log export for SIEM and ITSM tools

SCIM connects your identity directory to Proton Pass. User lifecycle events in your IdP propagate automatically — no manual steps, no support tickets.

Structured audit logs are exportable for SIEM ingestion. Feed credential access and admin event data into your existing monitoring pipeline or use the export for compliance evidence packages.

SIEM integration is available on Pass Professional and activated upon request — contact the team to set it up.

CLI access for DevOps and automation workflows

The Proton Pass CLI gives engineers terminal access to the vault without the GUI. Retrieve credentials in scripts. Inject secrets into automation pipelines without hardcoding them in config files. The CLI uses the same end-to-end encryption as every other Proton Pass client — independently audited by Recruity Labs (January–April 2026). Credentials are decrypted locally, not on a server.

Available on Pass Professional.