# MacStadium Docs ## Docs - [MacStadium cloud hosting for Apple hardware](https://docs.macstadium.com/macstadium/macstadium-overview/macstadium-overview.md): MacStadium hosts Apple hardware for enterprise: bare metal Macs, Orka macOS virtualization, and cloud access, in MacStadiu…
# MacStadium Docs ## Docs - [MacStadium cloud hosting for Apple hardware](https://docs.macstadium.com/macstadium/macstadium-overview/macstadium-overview.md): MacStadium hosts Apple hardware for enterprise: bare metal Macs, Orka macOS virtualization, and cloud access, in MacStadium data centers, AWS, or on-prem. - [MacStadium Portal for subscriptions and support](https://docs.macstadium.com/macstadium/macstadium-overview/macstadium-portal.md): Manage MacStadium subscriptions and support at portal.macstadium.com. A business email is required to register; personal email domains are not accepted. - [Viewing your environment in My Cloud](https://docs.macstadium.com/macstadium/macstadium-overview/ip-plan.md): My Cloud in the MacStadium Portal shows your environment by data center: public servers, firewalls, VPN credentials, network allocations, and host assignments. - [First-Time SSO Login to MacStadium Portal](https://docs.macstadium.com/macstadium/account-management-and-saml/first-time-sso-login-to-macstadium-portal.md): SSO login to the MacStadium portal with Okta, Azure AD, or Google Workspace. Your account admin must enable SSO before you can follow these steps. - [Troubleshooting Credential Issues](https://docs.macstadium.com/macstadium/account-management-and-saml/troubleshooting-credential-issues.md): Fix MacStadium Portal and service credential issues: verify your email, reset your password, or find server credentials in the Portal under Services. - [Add a new user to your MacStadium account](https://docs.macstadium.com/macstadium/account-management-and-saml/add-a-new-user.md): Invite team members to your MacStadium account, assign roles, and manage user-specific permissions from the MacStadium Portal's account management settings. - [Two-Factor Authentication (2FA)](https://docs.macstadium.com/macstadium/account-management-and-saml/two-factor-authentication-2fa.md): MacStadium offers the ability for customers to enable two-factor authentication (2FA) when logging into portal.macstadium.com. Two-factor authentication. - [SAML single sign-on for MacStadium accounts](https://docs.macstadium.com/macstadium/account-management-and-saml/saml-sso.md): Set up SAML SSO for your MacStadium organization to manage user authentication and access through your identity provider. Supports Okta, Azure AD, and Google. - [Enable SAML SSO with Okta](https://docs.macstadium.com/macstadium/account-management-and-saml/enable-saml-sso-with-okta.md): Admin: configure SAML SSO for MacStadium Portal via Okta. Save the MacStadium certificate, configure the Okta app, and log in at portal.macstadium.com/sso. - [Enable SAML SSO with Microsoft Entra ID](https://docs.macstadium.com/macstadium/account-management-and-saml/enable-saml-sso-with-azure-active-directory.md): Set up SAML SSO for the MacStadium Portal with Microsoft Entra ID (Azure AD): create the enterprise app, configure SAML, and share metadata. - [Enable SAML SSO with Google Workspace Federation](https://docs.macstadium.com/macstadium/account-management-and-saml/enable-saml-sso-with-google-workspace-federation.md): Configure SAML SSO for MacStadium Portal via Google Workspace. Create a custom SAML app in Google Admin, download metadata, and send it to MacStadium. - [MacStadium vendor onboarding and management](https://docs.macstadium.com/macstadium/billing/vendor-management.md): Complete vendor onboarding for MacStadium by filling out the Zip vendor profile form and submitting it to the billing and legal teams for approval processing. - [Access and download MacStadium invoices](https://docs.macstadium.com/macstadium/billing/accessing-invoices.md): Access PDF invoices for each MacStadium subscription in the MacStadium Portal under the Billing tab. Contact billing to consolidate multiple statements. - [Fix a declined credit card on MacStadium](https://docs.macstadium.com/macstadium/billing/credit-card-declined.md): MacStadium uses fraud protection that may flag legitimate transactions. If your card is blocked at signup, contact support to process your order manually. - [Canceling a MacStadium Subscription](https://docs.macstadium.com/macstadium/billing/canceling-a-macstadium-subscription.md): How to cancel your MacStadium subscription: click Cancel Service in the portal. Servers go offline within 24 hours, no refund for the current period. - [Master Services Agreement](https://docs.macstadium.com/macstadium/legal-and-compliance/master-services-agreement.md): MacStadium Master Subscription Services Agreement v2.0: governing legal terms for all MacStadium services, referencing the SLA and Acceptable Use Policy. - [Service Level Agreement](https://docs.macstadium.com/macstadium/legal-and-compliance/service-level-agreement.md): MacStadium guarantees 99.9% monthly uptime. This SLA defines what counts as an outage, how service credits are calculated, and how to file a claim. - [Acceptable Use Policy](https://docs.macstadium.com/macstadium/legal-and-compliance/acceptable-use-policy.md): MacStadium Acceptable Use Policy (Exhibit B of the MSSA): prohibited actions and restrictions governing customer use of all MacStadium services. - [Copyright and Trademark Policy](https://docs.macstadium.com/macstadium/legal-and-compliance/copyright-and-trademark-policy.md): MacStadium copyright and trademark policy: how to submit DMCA notices, report trademark infringement, and what happens after a report is filed. - [MacStadium security and compliance overview](https://docs.macstadium.com/macstadium/legal-and-compliance/security.md): Review MacStadium security policies, compliance certifications, and trust documentation. Visit trust.macstadium.com for current audit and compliance records. - [MacStadium support plans and services](https://docs.macstadium.com/macstadium/support/support.md): Compare MacStadium support tiers: Business, Pro, and Premium, with 24/7 monitoring, Remote Hands, and engineering support for networking and virtualization. - [MacStadium Support Tiers](https://docs.macstadium.com/macstadium/support/macstadium-support-tiers.md): MacStadium offers Basic, Pro, and Premium support. See response time SLAs, support hours, and what's included in professional services before you decide. - [Mac Configuration Assistance](https://docs.macstadium.com/macstadium/support/mac-configuration-assistance.md): MacStadium Remote Hands Service covers basic hardware and OS setup to ensure access to the Mac via remote SSH, VNC, or screen sharing. - [MacStadium Remote Hands hardware support](https://docs.macstadium.com/macstadium/support/remote-hands-service.md): MacStadium Remote Hands covers hardware diagnosis, network issues, OS password recovery, factory restore, and OS service changes on customer request. - [Update regarding CVE-2026-65400](https://docs.macstadium.com/CVE-2026-65400.md): MacStadium's response to CVE-2026-65400, the macOS Screen Sharing vulnerability: TCP 5900 is blocked at the network edge, SSH tunnel guidance included. - [Orka macOS virtualization platform overview](https://docs.macstadium.com/orka/orka-overview/orka-overview.md): Orka by MacStadium: macOS virtualization on Apple silicon with Kubernetes-native scheduling. Supports CI/CD, VDI, and AI workloads in cloud or on-prem. - [Orka tools, CLI downloads, and CI/CD plugins](https://docs.macstadium.com/orka/orka-overview/tools-integrations.md): Download Orka3 CLI binaries for macOS, Linux, and Windows, plus Orka VM Tools and CI/CD integrations for Jenkins, GitHub Actions, GitLab, and Buildkite. - [Orka compatibility matrix for macOS and hardware](https://docs.macstadium.com/orka/orka-overview/compatibility-matrix.md): Supported macOS versions, host OS requirements, and Orka cluster compatibility by hardware (M1/M2/M4, Intel). Verify your configuration before deploying. - [Deploy your first VM with the Orka3 CLI](https://docs.macstadium.com/orka/quick-start-guides/orka3-cli-quick-start.md): Get started with the Orka3 CLI: configure your API URL, log in, list nodes and images, deploy VMs, commit changes to a new base image, and clean up. - [Deploy your first VM with the Orka3 REST API](https://docs.macstadium.com/orka/quick-start-guides/orka3-api-quick-start.md): Get started with the Orka3 REST API: authenticate with a CLI token, deploy VMs, manage images, and build custom integrations with your Orka cluster. - [Orka Web UI quick start guide](https://docs.macstadium.com/orka/quick-start-guides/web-ui-quick-start.md): Get started with the Orka Web UI: browse nodes and images, create VM configs, deploy VMs, connect via Screen Sharing, and save changes as a new base image. - [Orka CI/CD integrations quick start guide](https://docs.macstadium.com/orka/quick-start-guides/cicd-integrations-quick-start.md): Step-by-step setup for Orka's CI/CD integrations: GitHub Actions, GitLab, Jenkins, Packer, TeamCity, and Buildkite. Includes connecting to your Orka cluster. - [Cluster Access Management: Overview](https://docs.macstadium.com/orka/orka-cluster-access/cluster-access-management-overview.md): Orka access control overview: SSO login, RBAC roles, namespaces, and role bindings. Covers Admin, Tech, and service account permissions across namespaces. - [Authentication and RBAC](https://docs.macstadium.com/orka/orka-cluster-access/orka-authentication-and-rbac.md): How Orka handles authentication and authorization: OIDC provider options, default RBAC roles and bindings, group mapping configuration, and migration guidance. - [Understanding Orka Credentials](https://docs.macstadium.com/orka/orka-cluster-access/understanding-orka-credentials.md): Learn how Orka's three credential systems work, when to use each, and how to avoid the common mistake of using short-lived tokens in CI/CD pipelines. - [Customer Portal: Manage Account Users](https://docs.macstadium.com/orka/orka-cluster-access/customer-portal-manage-account-users.md): Manage Orka cluster users via the MacStadium Customer Portal: invite new members, assign Admin, Tech, or Billing roles, and control namespace access. - [Log in to your Orka cluster for the first time](https://docs.macstadium.com/orka/orka-cluster-access/orka-cluster-access-the-cluster.md): Complete the cluster invitation process, connect via VPN, get your Orka API URL, and log in. Covers first-time registration and CLI authentication steps. - [Orka Cluster: Manage Access to Resources](https://docs.macstadium.com/orka/orka-cluster-access/orka-cluster-manage-access-to-resources.md): Admin guide: create namespaces, add subjects to role bindings, and isolate Orka resources for specific users, teams, or CI/CD service accounts. - [Orka Cluster: Manage Service Accounts](https://docs.macstadium.com/orka/orka-cluster-access/orka-cluster-manage-service-accounts.md): Admin guide: create and manage Orka service accounts for CI/CD integrations. Service accounts use 1-year tokens and bypass browser SSO login. - [MSDC Network Requirements](https://docs.macstadium.com/orka/networking-with-orka-at-macstadium/msdc-network-requirements.md): Network requirements for Orka clusters at MacStadium data centers in Atlanta, Dublin, and Las Vegas, including reserved address ranges and custom subnets. - [Connect to your Orka cluster via VPN](https://docs.macstadium.com/orka/networking-with-orka-at-macstadium/vpn-connection.md): Connect to your Orka cluster's Cisco ASAv via VPN with OpenConnect or Cisco AnyConnect. Required before managing VMs or configuring cluster networking. - [Built-In Orka Domains](https://docs.macstadium.com/orka/networking-with-orka-at-macstadium/built-in-orka-domains.md): Use your company.orka.app domain instead of raw Orka API IPs. Covers hosts file setup, HTTPS access, and certificate trust for the Orka API. - [External Custom Domains](https://docs.macstadium.com/orka/networking-with-orka-at-macstadium/external-custom-domains.md): Configure a custom domain for your Orka cluster using a TLS certificate. Covers certificate upload, domain mapping, Ingress configuration, and tool setup. - [Conne…