Skip to main content
v2026.11,610 entries · CC-BY 4.0

DocuSign SSO: Which Plan Includes It, and What IT Will Ask

Single sign-on is not included at any of DocuSign’s published self-serve prices — every tier routes you to sales. What the upgrade actually involves, what Entra ID, Okta and Shibboleth each require, what your security office will ask beyond SAML, and whether switching vendors to avoid the fee saves anything.

Ask about DocuSign SSO: Which Plan Includes It, and What IT Will Ask

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Written and maintained by CASRAI Editorial Board

Last updated

Most people searching for “DocuSign SSO” are not looking for a configuration walkthrough. Docusign’s own admin documentation already covers claiming a domain and wiring up an identity provider, and it covers it better than any third-party page will. The question that actually stalls a purchase is the one the documentation does not answer: which plan do I have to be on before that admin screen even exists, and what does getting there cost?

The short answer, verified against Docusign’s published plan comparison as of August 2026: single sign-on is not included at any self-serve price. Personal, Standard and Business Pro all show “Access management & SSO” as Contact sales — it is not a checkbox you toggle on the plan you already bought. That is why so many research offices discover the problem in the same order: signature budget approved, pilot running, then institutional IT declines to approve a tool that cannot federate against the campus identity provider, and the renewal quote arrives with a different number on it.

This page is for the person at that gate. It covers which plan carries SSO, what Docusign requires before SSO can be switched on at all, what Microsoft Entra ID, Okta and Shibboleth each involve, what your identity and security team will demand beyond SAML, and how the same requirement is priced across the alternatives — including the arithmetic on whether switching vendors to dodge an SSO upgrade actually saves anything. Often it does not.

Editorial disclosure: Some links on this page are CASRAI referral links. If you sign up through one, CASRAI may earn a commission at no extra cost to you — this helps fund our nonprofit mission. We only recommend tools our editorial team has independently researched, and we say plainly where a tool is not the right fit. Read our full disclosure policy →

Tip: try code CASRAI at checkout for 15% off, if the offer is currently active for this program — codes vary by vendor and aren’t guaranteed.

Which DocuSign plan includes SAML SSO, and what the upgrade actually costs

Docusign’s public eSignature plan page (checked August 2026) lists four tiers. Three carry a published price; the fourth does not:

Plan Price (annual billing) Seats Envelopes Access management & SSO
Personal $11/month 1 user 5 per month Contact sales
Standard $30/user/month Up to 50 users 100/user/year Contact sales
Business Pro $45/user/month Up to 50 users 100/user/year Contact sales
Enhanced Plans Custom quote 50+ users Custom limit Contact sales

Read that last column carefully, because it is the whole story. SSO is not a Business Pro feature that Personal lacks. It sits outside the self-serve ladder entirely: every tier routes you to a sales conversation for it. In practice that means an Enhanced (enterprise) agreement, and Enhanced agreements are quoted, not listed — which is precisely why nobody can tell you in advance what your SSO will cost.

What this does to a budget. A twelve-seat research office on Business Pro is paying $45/user/month on annual billing, or $6,480/year. Adding SSO does not add a line item to that invoice; it moves the whole account onto a differently-structured agreement. The number that comes back depends on your seat count, term length, envelope volume, and what else gets bundled in. We cannot tell you what it will be, and neither can anyone else who is not your Docusign account executive. Anyone publishing a specific “DocuSign SSO price” is guessing.

What you can do is establish the ceiling before the conversation starts. Get a like-for-like quote from at least one alternative that publishes its SSO tier openly, so the Enhanced quote arrives with something to be compared against rather than being the only number in the room. That is the single most useful thing to do at this stage, and it takes an afternoon.

Sign.Plus is the usual like-for-like comparator here, because it publishes a per-seat price for the tier that carries SSO rather than hiding it behind a form. We cover the product in depth in our Sign.Plus review; the relevant fact for this page is that its Enterprise tier is $49.99/user/month on annual billing (verified on sign.plus/pricing, August 2026), and SSO is listed as included at that tier.

See Sign.Plus pricing and its SSO tier →

What Docusign requires before SSO can be switched on at all

Plan tier is a necessary condition, not a sufficient one. Docusign’s identity configuration lives in Docusign Admin (organization management), and its support documentation is explicit that single sign-on requires Docusign Admin — the SSO screens are administered by organization administrators with full administrative rights, not by an account administrator on a standard plan.

Two prerequisites in particular catch research offices out:

  1. Domain claiming. Before you can federate, your organization has to claim and verify the email domain your users sign in with. In Docusign Admin this is an explicit action — the Domains section, “Claim Domain”, enter the domain, verify ownership. Until that domain is claimed, there is nothing for an identity provider to be authoritative over.
  2. Organization-level access. An organization has to exist, with an administrator who holds full rights over it. If your Docusign presence grew organically — three departments, three separate accounts, three separate billing relationships — you do not have that structure yet, and creating it is a project of its own. See the consolidation section below.

Neither of these is difficult. Both take longer than the person who scoped the project assumed, because both need someone who controls DNS for the domain and someone who has authority to consolidate accounts. Those are frequently two different departments, and neither of them reports to the research office.

DocuSign with Entra ID, Okta, and Shibboleth: what each integration requires

All three are SAML 2.0 relationships at bottom, so the mechanics rhyme: the identity provider asserts who the user is, Docusign consumes the assertion, and users stop having a Docusign-specific password. What differs is who does the work and what else comes along with it.

Microsoft Entra ID (formerly Azure AD)

The most common case in a university or hospital that is already Microsoft-centred. Docusign is a pre-integrated gallery application in Entra ID and Microsoft publishes a maintained configuration tutorial for it, which means your identity team is following a documented path rather than hand-building a SAML relationship. If your institution already runs Entra ID for Microsoft 365, this is the lowest-friction option and the one your IT team will most likely propose.

Okta

Functionally equivalent for your purposes: a maintained integration, SAML assertion, group-based assignment. If your institution runs Okta as its workforce identity provider, the work sits with the Okta administrators and the Docusign organization administrator, and the coordination cost is mostly calendar time between two teams.

Shibboleth and federated access

This is where a lot of research-sector procurement goes sideways, and it is worth being precise about the distinction. Shibboleth is a SAML implementation, so “supports SAML 2.0” is technically compatible with it. But research and education institutions frequently do not want a bilateral SAML relationship with each vendor — they want the vendor to be a service provider inside a federation, such as InCommon in the United States or an eduGAIN-interfederated national federation elsewhere, so that metadata, trust and attribute release are managed centrally rather than one contract at a time.

Federation membership is a much narrower capability than generic SAML support, and many e-signature vendors do not have it. If your requirement is genuinely “must be an InCommon service provider” rather than “must support SAML”, verify that directly with the vendor before you buy — for Docusign, for Sign.Plus, and for every alternative on your shortlist. Do not infer it from a “SAML 2.0 supported” line on a feature matrix, and do not accept it from a page like this one. Ask the vendor, in writing, naming the federation.

If you are still mapping the difference between bilateral SSO and federated access, our explainers on OpenAthens versus Shibboleth and EZproxy and on SeamlessAccess cover the landscape your library and identity teams are working in.

SCIM provisioning and deprovisioning: the requirement that fails security review

SSO answers “can this person sign in?” It does not answer “does this person still have an account?” Those are different controls, and a security review that is doing its job will test the second one.

The scenario your information security office is thinking about: a postdoc leaves. Their institutional account is disabled the day they separate. If the e-signature platform is federated, they can no longer authenticate — good. But their user record still exists, still counts against your seat licence, may still be a named recipient on in-flight envelopes, and may still appear as an authorised signer in an audit trail. Without automated deprovisioning, someone has to remember to remove them manually, and in a research office with high turnover nobody ever does.

SCIM (System for Cross-domain Identity Management) is the standard that closes this. It lets the identity provider create, update and deactivate accounts in the downstream application automatically as people join, change roles and leave. Docusign supports SCIM-based user and group provisioning through Docusign Admin — its user list marks SCIM-managed accounts distinctly — so the capability exists on the same organization-management footing as SSO itself.

The questions worth asking any vendor, in this order:

  • Is SCIM provisioning supported, and at which plan tier?
  • Does deactivation in the IdP actually deactivate the downstream account, or merely block login?
  • Does a deactivated seat free up a licence, or continue to be billed until someone deletes it manually?
  • Are group memberships synced, so that signing authority follows the role rather than the person?
  • What happens to envelopes in flight when a signer is deprovisioned mid-workflow?

That last one is not hypothetical. Multi-year grant agreements and IRB documents routinely sit in a pending state for weeks.

What institutional IT will ask before approving any e-signature tool

SSO is one line on a longer form. If you are buying into a university or academic medical centre, the review will be broader than the identity question, and knowing the full list up front is what prevents three rounds of back-and-forth.

  • A completed vendor security assessment. In US higher education this is very often the HECVAT, the community standard questionnaire; many institutions will accept a published HECVAT from the vendor’s own library rather than making you chase a bespoke one. Ask the vendor whether they have one on file before you ask them to fill one out.
  • SOC 2 Type II or ISO/IEC 27001 evidence, current, with the report available under NDA rather than just a badge on a marketing page.
  • Data residency. Where documents are stored and processed. For EU and UK institutions this is frequently the binding constraint, not the price.
  • Accessibility conformance — a VPAT or equivalent. Public institutions in particular cannot approve a signing workflow that a screen-reader user cannot complete.
  • The regulatory overlay for your specific documents. If you are signing anything touching protected health information you will need a business associate agreement and the controls behind it — see our guide to HIPAA-compliant e-signature software. If the signature is part of a regulated clinical record, 21 CFR Part 11 applies and is a genuinely higher bar than ordinary e-signature validity — it requires validated systems, secure audit trails and specific signature-manifestation requirements, and vendors differ sharply on whether they support it. If export-controlled material is involved, see ITAR-compliant storage.
  • MFA inheritance. Whether the tool honours the multi-factor step your IdP already enforces, rather than layering its own separate second factor on top or — worse — allowing a local password bypass that survives federation.

That last point matters more than it sounds. An SSO deployment that still permits local-password login for some users has not actually removed the credential; it has just added a second door. Ask specifically whether local authentication can be disabled organization-wide once federation is live.

Compare Sign.Plus Enterprise seat pricing →

SSO across the alternatives: who includes it and who charges for it

Here is the part most affiliate pages get wrong, so we will do the arithmetic in public rather than assert a conclusion.

Sign.Plus gates SSO to its Enterprise tier. It is not a free workaround. As of August 2026 its published plans are Free, Personal ($9.99/month annual), Professional ($19.99/user/month annual), Business ($29.99/user/month annual) and Enterprise ($49.99/user/month annual) — and SSO appears at Enterprise only. So the comparison is not “paid SSO versus free SSO.” It is “an unpublished enterprise quote versus a published enterprise price.”

Requirement Docusign Sign.Plus
Entry paid tier Personal, $11/month Personal, $9.99/month
Mid team tier Standard, $30/user/month Business, $29.99/user/month
Highest published per-seat tier Business Pro, $45/user/month Enterprise, $49.99/user/month
Tier that carries SSO Contact sales at every tier Enterprise (published price)

Note what that table does not show: a saving. At list price, Sign.Plus Enterprise ($49.99/user/month) is more expensive per seat than Docusign Business Pro ($45/user/month). Switching only comes out ahead if the Docusign Enhanced quote for your seat count lands above $49.99/user/month — which it may well do, since Enhanced agreements are structured for 50+ seats and are typically not priced attractively for a twelve-person office that only wants one feature. But it may not. You do not know until you have the quote, and this page cannot know it for you.

What is genuinely different is the shape of the information, not the size of the number. One vendor lets you calculate your annual cost from a public page before you talk to anyone; the other does not. For a research office that has to put a figure in a budget request before it is allowed to start a procurement, that difference has real value — but it is a procurement-process advantage, not automatically a cheaper invoice.

Our per-vendor breakdowns cover the rest of the shortlist: Docusign pricing for research offices, Adobe Acrobat Sign pricing, PandaDoc pricing, and the wider field in Docusign alternatives and electronic signature software for research offices. If your shortlist is down to two, Docusign vs Adobe Sign compares them directly.

Domain claiming and account consolidation when staff signed up individually

The most common blocker is not technical. It is that Docusign arrived at your institution the way most SaaS does — one person expensed a Personal plan to get a subaward signed, then a department bought Standard, then a core facility bought its own. By the time SSO is on the table you have several unrelated accounts, several billing relationships, and a set of users whose Docusign identity is tied to a personal or departmental email rather than an institutional one.

Claiming the domain is what forces this into the open, because claiming a domain asserts organizational authority over every account using an email address at that domain. Sequence it deliberately:

  1. Inventory first. Find every existing account on your domain before you claim it, not after. Finance can usually produce this faster than IT can — search expense records for the vendor name.
  2. Decide what happens to each one. Merge into the organization, leave standalone, or retire. Retiring an account with completed envelopes in it means deciding where those executed documents live afterwards.
  3. Export completed documents and their certificates of completion before any account is closed or migrated. The signed PDF alone is not the evidentiary record — the audit trail behind it is what makes the signature defensible, and it does not always travel with the document.
  4. Claim the domain and verify it via DNS. This needs whoever administers your institutional DNS, which is rarely the research office.
  5. Configure the identity provider, then disable local authentication — in that order, with a tested rollback, and not on the Friday before a grant deadline.

If you are migrating vendors rather than consolidating within one, everything above still applies, plus the re-papering of any agreement that is mid-signature. That cost is routinely underestimated and is the single best reason to stay put.

If SSO is the only reason you are upgrading, price the alternatives first

Here is our honest read, stated plainly, including the cases where the answer is “do not switch.”

Stay with Docusign, and stop reading here, if you are already deployed and mid-implementation. Go to Docusign’s admin documentation, claim your domain, and configure your identity provider. Migrating an in-flight rollout to save a licence tier is a false economy: you will spend more in staff time on re-papering active agreements, retraining signers and re-validating workflows than the tier difference recovers. This is doubly true if you have templates, integrations into a CTMS or grants system, or Part 11-relevant workflows already validated. Switching e-signature vendors to avoid an SSO upgrade fee is almost never worth it once you are past pilot.

Stay with Docusign if your requirement is federation membership — InCommon, eduGAIN, or a national research and education federation — and you have confirmed Docusign meets it while an alternative has not. Generic SAML support is not the same capability, and swapping a vendor that clears your federation requirement for one that has not been verified against it is a straightforward downgrade regardless of price.

Look seriously at alternatives, including Sign.Plus, if you are genuinely pre-purchase or at a renewal boundary; your seat count is well under the 50-user threshold where Enhanced pricing is designed to make sense; you need a defensible number in a budget request before procurement will engage; and your identity requirement is a single corporate IdP (Entra ID or Okta) rather than federation membership. That is a real and reasonably common set of conditions in a research office — and it is the only set of conditions under which this comparison is worth your afternoon.

Sign.Plus is not the right answer if you need 21 CFR Part 11-validated workflows, deep integration with an existing enterprise agreement, or federation membership you have not verified. In those cases the incumbent, or an enterprise agreement you already hold, wins on the merits — and no referral commission changes that.

Try Sign.Plus free before you commit →

Frequently asked questions

Does DocuSign Business Pro include SSO?

No. As of August 2026, Docusign’s published plan comparison shows “Access management & SSO” as Contact sales for Personal, Standard and Business Pro alike. SSO is not part of any self-serve tier; it requires a sales conversation, in practice an Enhanced (enterprise) agreement.

How much does DocuSign SSO cost?

Docusign does not publish a price for it. Enhanced plans are quoted based on seat count, term, envelope volume and bundled features, so the figure depends on your specific account. Treat any specific dollar amount you find online as unverified — get the quote from your account team, and get a comparison quote alongside it so the number has context.

Do I need Docusign Admin to set up SSO?

Yes. Docusign’s support documentation states that single sign-on requires Docusign Admin, and identity settings — domains, identity providers, SCIM provisioning — are managed by organization administrators with full administrative rights.

Does DocuSign work with Microsoft Entra ID and Okta?

Yes. Docusign is a pre-integrated gallery application in Entra ID with a Microsoft-maintained configuration tutorial, and it integrates with Okta as a SAML 2.0 service provider. Both require the organization-level access described above before the integration can be configured.

Does DocuSign support SCIM provisioning and automatic deprovisioning?

Yes — Docusign supports SCIM-based user and group provisioning through Docusign Admin, with SCIM-managed users flagged in the organization’s user list. Confirm with your account team which agreement tier makes it available to you, since it sits behind the same organization-management layer as SSO.

Is DocuSign an InCommon service provider?

Verify this directly with Docusign for your specific agreement rather than relying on a “SAML 2.0 supported” feature line. Federation membership is a narrower capability than SAML support, it varies by product and region, and it is exactly the kind of requirement that is expensive to discover after signature. Ask in writing, naming the federation.

Does Sign.Plus include SSO on cheaper plans than DocuSign?

Sign.Plus includes SSO on its Enterprise tier at a published $49.99/user/month on annual billing (verified August 2026), so unlike Docusign you can see the number without a sales call. But it is not cheaper at list than Docusign’s Business Pro tier ($45/user/month) — the potential saving depends entirely on what Docusign’s Enhanced quote comes back at for your seat count. Do the arithmetic with your real numbers before assuming either direction.

Can I keep local passwords enabled alongside SSO?

Technically you often can, but your security office will usually require that you do not. Leaving local authentication enabled means the credential you federated away still works, which defeats most of the point of the deployment. Ask your vendor whether local login can be disabled organization-wide once SSO is live, and plan a tested cutover rather than a flag flip.

Related reading on CASRAI

Pricing and plan-feature claims on this page were verified against Docusign’s published eSignature plan comparison and sign.plus/pricing in August 2026. Vendors change pricing and tier packaging without notice — confirm current figures with the vendor before making a purchasing decision.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 44,322 indexed passages, and every answer cites the ones it drew on.