| Prisma Browser Desktop | Prisma Browser Extension | Prisma Browser for Mobile |
| Full support | Full support | Not available |
The Identity Provider Login control allows administrators to govern
SAML-based SSO authentication through enterprise identity providers. When a user
attempts to authenticate through an identity provider such as Okta, Entra ID,
Ping Identity, or Google Workspace, the Prisma Browser intercepts the SAML
response and enforces the configured policy.
This control supports four enforcement modes, enabling administrators to allow or
block login through all identity providers, or target specific providers by
domain. The control is configured within the Access & Data policy rule
wizard under .
To set the Identity Provider Login control: