Skip to main content
The Identity and Access settings page is where administrators configure how members authenticate into the Conversion workspace. From here you can require multi-factor authentication, verify your domain, set up SAML single sign-on (SSO), and connect SCIM for automatic provisioning.
Only administrators can access the Identity and Access page. See Members for more on roles.

Security

Configure security requirements for workspace members.

Require multi-factor authentication (MFA)

When enabled, members are required to sign in with MFA to access the workspace. Members signing in with SSO are exempt.

Verification

Verify ownership of your workspace’s domain to enable SSO for members. Click Set up DNS next to the domain to see the TXT record to add at your DNS provider: Add the record, then return to the dialog and click Verify. Once the record is found, the domain shows a green Verified badge.
Domain verification is a prerequisite for enabling SAML SSO. The SAML controls stay disabled until the domain is verified. The same verification is shared with File hosting.

Single sign-on (SSO)

Configure SAML SSO as an authentication method for members. For a step-by-step walkthrough of connecting your identity provider, see Set up your identity provider for SAML SSO.

Enable SAML

When enabled, members are presented with the option to sign in with SAML SSO. The first time, click Enable SAML SSO to open the Set up SAML SSO modal and paste in your identity provider’s metadata XML. Once a configuration exists, the row shows a toggle to turn SAML on or off and a settings icon to reopen the modal and update the metadata.

Require SSO for this business

When enabled, members are required to sign in with SAML SSO to access the workspace. Business owners can always sign in with any method to avoid lockout.

Enable just-in-time (JIT) provisioning

When enabled, accounts are automatically created for new members the first time they sign in using SAML SSO. Without JIT, members must be invited from the Members page before they can sign in.
Require SSO for this business and Enable just-in-time (JIT) provisioning are only available while Enable SAML is on.

SCIM

Automatically provision members from your identity provider (IdP) using SCIM. The SCIM section is available once SAML is enabled. Click Add token to open the Generate a SCIM token dialog. It shows the Base URL to enter in your IdP; click Confirm and generate to create the token. Copy both values into your IdP’s SCIM provisioning settings.
The token is shown only once. Click I have copied the token after saving it somewhere secure. Make sure your IdP supports pushing new users and pushing user updates.
Each token you’ve generated is listed with the date it was created and its last four characters. Click the trash icon to delete a token. Deleting a token immediately revokes access for any identity provider using it to provision members, and cannot be undone.