Enterprise and SAML

Enterprise Accounts and SAML Single Sign-On in Brief

On the Enterprise plan, an enterprise account sits above many organizations with shared policies, billing and audit logs, and connects GitHub 29 to the company's identity provider (IdP), such as Microsoft Entra ID or Okta. None of it was run here; this summary follows GitHub's Enterprise Cloud documentation. There are two identity models. With SAML single sign-on, people keep their own GitHub accounts and must also authenticate at the IdP before reaching the organization's resources, for a session of 24 hours unless the IdP sets another. A personal access token or SSH key works against such an organization only after you authorize it for SSO, so a sudden 403 that mentions SAML usually means an unauthorized token. With Enterprise Managed Users, the IdP creates and suspends the accounts through SCIM (named like sam_booknest), and they cannot contribute outside the enterprise.

Managed users also underpin GitHub Enterprise 29 Cloud with data residency, a separate GHE.com subdomain that stores code in a chosen region (the EU, Australia, the United States or Japan in 2026). GitHub Enterprise Server is the self-hosted edition, where the admin/organizations endpoint of The BookNest Organization exists. BookNest needs none of this; Enterprise earns its price when an auditor's question about access must be answered from the company's IdP.