Only administrators can access the Identity and Access page. See Members for more on roles.
Security
Configure security requirements for workspace members.Require multi-factor authentication (MFA)
When enabled, members are required to sign in with MFA to access the workspace. Members signing in with SSO are exempt.Verification
Verify ownership of your workspace’s domain to enable SSO for members. Click Set up DNS next to the domain to see the TXT record to add at your DNS provider:
Add the record, then return to the dialog and click Verify. Once the record is found, the domain shows a green Verified badge.
Domain verification is a prerequisite for enabling SAML SSO. The SAML controls stay disabled until the domain is verified. The same verification is shared with File hosting.
Single sign-on (SSO)
Configure SAML SSO as an authentication method for members. For a step-by-step walkthrough of connecting your identity provider, see Set up your identity provider for SAML SSO.Enable SAML
When enabled, members are presented with the option to sign in with SAML SSO. The first time, click Enable SAML SSO to open the Set up SAML SSO modal and paste in your identity provider’s metadata XML. Once a configuration exists, the row shows a toggle to turn SAML on or off and a settings icon to reopen the modal and update the metadata.Require SSO for this business
When enabled, members are required to sign in with SAML SSO to access the workspace. Business owners can always sign in with any method to avoid lockout.Enable just-in-time (JIT) provisioning
When enabled, accounts are automatically created for new members the first time they sign in using SAML SSO. Without JIT, members must be invited from the Members page before they can sign in.Require SSO for this business and Enable just-in-time (JIT) provisioning are only available while Enable SAML is on.