Let your team log in with your existing identity provider instead of a separate Zynty password.
In your identity provider, create a new SAML application. Zynty's own metadata (ACS URL and Entity ID) is shown on the Security settings page for you to paste in.
Paste your identity provider's metadata URL (or upload the XML file) into Zynty's SSO configuration.
Use Test connection to confirm a login round-trip succeeds before making SSO mandatory, this avoids locking your whole team out over a misconfigured attribute mapping.
Once verified, enable Require SSO to disable password login entirely, or leave it optional during a transition period.