Enable Enterprise Controlled Encryption (ECE)
Configure Single Sign-On OIDC
Verkada currently only supports Okta, Microsoft Entra ID (Azure AD), and Google Workspace as identity providers for Single Sign-On with OIDC. For a detailed setup guide, refer to the following:
OIDC SSO must be enabled in your organization to enable ECE.

Update Command mobile app
To ensure a smooth user experience, ask all users in your organization to update their Verkada Command mobile app. The app updates automatically unless auto-update is disabled. This step is required only for users of the Command mobile app.
iOS: Verkada Command
Android: Verkada Command
There is no need to update the Verkada Pass app.
Enable ECE
Under Generate Key:
a. Click Generate Key b. Download the encryption key. c. Add the encryption key to your identity provider. d. Click Continue.
The encryption key for ECE (step 4) should only be generated once. Use this encryption key to create the mapping in the OIDC provider. After verification, avoid regenerating the encryption key and updating the OIDC provider’s mapping.
Example template of the encryption key file:
File name: <command-org-name>_org_secret.txt
Format:
<display-name / variable-name>
<encryption-key>Add Encryption Key to Identity Provider
ECE is currently only supported on Okta and Microsoft Entra ID (Azure AD). Follow the steps below based on your identity provider.
Need more help? Contact Verkada Support.
Last updated
Was this helpful?

