Add the provided TXT record to your domain’s DNS settings
3
Domain realm discovery
Domain realm discovery is automatically enforced for all managed domains
Users with email addresses from managed domains will be automatically redirected to your SSO provider and cannot use username/password authentication. Maintain at least one admin account with an email from a non-managed domain as backup.
After enabling SSO, you have control over which authentication methods your users can access.
Automatic SSO redirect for new users
When a new user enters an email address with a domain matching your SSO configuration, they are automatically redirected to authenticate through your identity provider instead of receiving an email invitation.This ensures that all users from your managed domains authenticate through your corporate identity provider from their first login.
Disable other login methods
By default, users can still authenticate through email/password or Google sign-in even after SSO is enabled. Organization admins can explicitly disable these alternative authentication methods to enforce SSO-only access.
1
Navigate to SSO settings
Go to Settings > SSO
2
Locate SSO enforcement section
Find the Enforce SSO-Only Authentication section (only visible after SSO is enabled)
3
Enable SSO-only enforcement
Toggle the switch to enable SSO-only enforcement and remove email/password and Google sign-in options
4
Confirm enforcement
After enabling, an Enforced badge will appear next to the section title
Users will only be able to authenticate through your identity provider after other methods are disabled. This provides complete control over authentication in your organization. Once enabled, the toggle switch is disabled and can only be re-enabled by detaching your SSO connection.
Restoring other login methods
If you need to restore email/password and Google sign-in options, you can do so by detaching your SSO connection. This automatically re-enables the default authentication methods.
Detaching SSO will remove your identity provider integration and restore standard authentication methods. Users will need to set up passwords if they haven’t already.
Backup admin access: Maintain at least one organization admin account that uses an email domain not configured for SSO. This ensures you can access your organization if your SSO provider becomes unavailable.