
Get the job done with a pro
From training to full-service marketing, our community of partners can help you make things happen.
How to Use Mailchimp Enterprise SSO
Overview
Mailchimp Enterprise SSO lets all users in a Mailchimp account, with a configured private domain, sign in through your identity provider (IdP) credentials, rather than with Mailchimp passwords. If your identity provider supports single sign-on (SSO), you can use it to log in to Mailchimp. Examples of IdP SSO providers include Microsoft Entra ID, Okta, and more.
Before you start
Please note:
- Enterprise SSO is available to Premium accounts
- Mailchimp supports only Open ID Connect protocol (OIDC)
- You must be the Owner of the account to set up this feature
- Mailchimp does not support service provider (SP) SSO, only IdP SSO
- We recommend reaching out to your company’s IT department to help you configure this feature. You'll need to complete certain steps within your company’s identity provider. If preferable, you can temporarily transfer the Owner role of your account to set up SSO.
Gather Settings From Your Identity Provider (IdP)
Mailchimp needs some information from your Identity Provider (IdP) to configure your SSO. You can use any provider that supports Open ID Connect protocol (OIDC). You will need to gather your Client ID, Client secret, and Config URL. Check below for the terminology used by some specific providers, such as:
Microsoft Entra ID
We recommend referring to Microsoft’s documentation on how to configure OIDC or our shortened guide to configuring your Entra tenant.
Additionally, download this preconfigured app manifest to simplify setup.
| Mailchimp field | Entra field | Where to find it in Entra |
|---|---|---|
| Client ID | Application (client) ID | Under Essentials on the Overview tab |
| Client secret | Client secret | Click the link under Client Credentials on the Overview tab |
| OIDC discovery URL | Open ID Connect metadata document | Select Endpoints on the Overview tab |
Okta
We recommend referring to Okta’s documentation on how to configure OIDC or our shortened guide to configuring your Okta application.
| Mailchimp field | Okta field | Where to find it in Okta |
|---|---|---|
| Client ID | Client ID | Under Client Credentials section of the General tab |
| Client secret | Client secret | Under Client Credentials section of the General tab |
| OIDC discovery URL | Open ID Server Discovery Endpoint | Create this manually using the format "https:///.well-known/openid-configuration", where is your Okta domain. |
Navigate to the OIDC SSO Settings
- When logged into the Owner account, click your profile icon and choose Account & billing.
- Click the Settings drop-down menu and choose Security.
- In the Security section, click Set up Single Sign-On
Configure your IdP Information in the SSO Settings
Adding your settings information from your Identity Provider will let your provider communicate with Mailchimp using the OpenID Connect protocol.
- Add your OIDC Discovery URL into the top-most open field.
- Click on the Get Configuration button.
- This prepopulates values into the Configuration section of the OIDC Settings.
- In the Enter your IdP’s OIDC details section, enter the information from your provider that you collected in advance. a. Enter your Client ID b. Enter your Client secret
- When you have entered all required details, click Save button.
Confirm Domains for SSO Enforcement
This is an interface for entering and managing the domains you would like to verify for use with single sign-on. Note that DNS changes can take up to 48 hours to propagate.
- Enter the domain of the workforce emails into the Domain name field.
- Select Add domain.
- Save the generated TXT host and TXT value. These must be added to the records through your DNS provider.
- Select Verify.
- Once the domain is configured, it will indicate Configured, when it was confirmed, and when it was last checked.
Enable SSO
Once your IdP’s information has been configured, you can enable SSO for your Mailchimp account and begin testing your SSO settings with specific secondary users in your Mailchimp account.
- Toggle on the Enable SSO.
- Navigate down to the Account members table. This will show you all secondary users in your Mailchimp account who can be used for testing.
- To select your test member, click the Switch to SSO button in the Available Actions column for the user.
Note: Account members may indicate issues that need to be resolved before you can Require SSO later. Please see FAQs below.
Configure User Invite Restrictions
Once your IdP’s information has been configured and SSO has been enabled for your Mailchimp account, it is possible to further secure your account by restricting future user invitations to this account to only work within your configured domains.
- Click on the toggle to the right of User Invite Restrictions.
Require SSO
Once you have tested SSO with at least one secondary user, you can choose to require SSO as the only login option for your Mailchimp account. Be aware that requiring SSO for your Mailchimp account will require that all accounts logging into your account are on one of the verified domains for your account.
- Toggle on the Require SSO.
Note: Account members may indicate issues that need to be resolved before you can Require SSO later. Please see FAQs below.
Microsoft Entra
Create the App Registration
- Sign in to the Microsoft Entra admin center.
- Go to Identity → Applications → App registrations
- Select New registration
- Enter these values:
- Name: Mailchimp Enterprise SSO
- Supported account types: Accounts in this organizational directory only (Single tenant)
- Redirect URI: Leave blank
- Select Register.
Note: The redirect URI is added when you upload the Mailchimp manifest. Leave it blank during this step.
Upload the Mailchimp manifest
- Open the App Registration you just created.
- In the left menu, select Manifest.
- Upload the Mailchimp-provided manifest file.
- Click Save to apply the changes.
Create a client secret
- In the App Registration, go to Certificates & secrets
- Under Client secrets, select New client secret
- Add a description such as Mailchimp Enterprise SSO.
- Choose an expiration that matches your organization's policy.
- Select Add.
- Copy the secret Value immediately and store it securely.
Note: Copy the secret Value, not the Secret ID. The Value is shown only once. If you leave the page without copying it, create a new secret.
Grant admin consent
Granting admin consent prevents assigned users from seeing an OAuth consent prompt on first sign-in.
- In the App Registration, go to API permissions
- Select Grant admin consent for
- Confirm when prompted.
Assign users
Creating the App Registration also creates a matching Enterprise Application (managed application) in your tenant. Do not create a separate Enterprise Application manually.
- From the App Registration Overview page, select Managed application in local directory.
- Or go to Enterprise applications, search for 'Mailchimp Enterprise SSO', and open it.
- Go to Properties.
- Set Assignment required? to Yes.
- Go to Users and groups.
- Add the users who should sign in to Mailchimp with SSO.
- Ensure your users in Entra have their email property set (this email claim is what will be used to match them with their verified email in Mailchimp when enabling SSO)
Note: Only users who are assigned here can sign in using this SSO application.
Collect values for Mailchimp
Enter these values (from the Gather Settings From Your Identity Provider (IdP) section above) in the Mailchimp Enterprise SSO settings when you are ready.
Troubleshooting Error States
User Not Invited
An Owner or Admin must invite the user's email address (on an SSO-configured domain) before they can access Mailchimp. If a user authenticates successfully through SSO, but has no active invitation or membership in the Mailchimp account:
We don't recognize this account. If your team uses Mailchimp, ask your admin to invite you.
An invite should be sent to the alias through the Mailchimp user invitation flow. You can grant account access by following the instructions here.
Domain Not Permitted
If an admin attempts to invite an email address outside the approved domains:
This account requires SSO. You can only invite users from configured domains.
Invites to email addresses outside of the configured domains will not be supported and will always generate an error.
IdP Unavailable or Timeout
If the SSO provider is unreachable during the SSO redirect:
Your identity provider is unavailable. Please try again. If the issue persists, contact your IT administrator.
Session Expired — Re-Authentication
When a Mailchimp session expires while the user is active, a re-authentication prompt appears. The user should select the link to return to the login page and sign in again through SSO.
Admin Reference
Viewing Users, Invites, and Roles
Navigate to Account & billing > Settings > Users to see all active account members with their assigned roles, pending invites, and the account Owner.
Client Secret Rotation
If the IdP client secret needs to be rotated, generate the new secret in your provider interface first and then update the secret in your management interface. To do that:
- Click your profile icon and choose Account & billing.
- Click the Settings drop-down menu and choose Security.
- In the Security section, click Manage SSO settings.
- Click on the arrow on the right-hand end of the OIDC settings block.
- Enter your new secret into the Client secret field.
- Click Save.
Profile Fields
First name, last name, and email address are sourced from your provider and are read-only in Mailchimp for SSO users. Additionally, the password fields will be blocked on the Profile page as they won't be used when SSO is enabled. Business profile, billing information, account name, and notification preferences remain editable in Mailchimp as usual, since these settings are relevant to your billing and company, not the logged-in user.
MFA
Mailchimp's built-in two-factor authentication is suppressed for SSO-authenticated sessions. MFA is enforced by your IdP / company policy. Users will not see a Mailchimp 2FA prompt — their IdP authentication challenge fires instead.
Technical Support
Have a question?
Paid users can log in to access email and chat support.