Set up single sign-on so everyone in your organization can sign in with Google, GitHub or Microsoft instead of a password, and control which email domains are allowed to use it. This is for organization owners and admins managing sign-in policy.
Overview
- A sign-in connection is your organization's policy for one provider — which email domains it accepts and what happens when someone new uses it.
- You can restrict connections to your own domains, require single sign-on for everyone, and turn connections off without breaking anyone's account.
- Every change here is written to your audit log, and signing in with a provider never changes anybody's role or permissions.
Add a sign-in connection
- Go to Settings → Sign-in.
- Under Sign-in connections, choose a provider to add.
- The connection is on straight away — anyone in your organization can now use that provider.
NoteIf a provider isn't offered, it hasn't been set up for the platform yet. Ask your InfraNest administrator.
Limit sign-in to your own email domains
By default a connection accepts any address. To narrow it:
- Open the connection you want to restrict.
- Type the domains you want to allow into Allowed email domains, one per line — or switch on Use our verified domains so the connection automatically follows the domains you've already verified.
- Check the row, which always shows what the restriction currently accepts.
- Subdomains are not included. Allowing
acme.comdoes not allowmail.acme.com. Add it separately if you need it. - Turning on "Use our verified domains" before you've verified any accepts everything. The row will say so when that happens.
Members who can't use any of your connections are protected: if a restriction would lock somebody out while single sign-on is required, InfraNest refuses to save it and names the people affected.
Require single sign-on
Switching on Require single sign-on turns off password sign-in for everyone in the organization.
Before you can enable it, InfraNest checks that nobody gets stranded:
- Confirm every member can use one of your connections.
- Make sure at least one owner has a passkey registered — register one in Profile → Security first if needed.
- Switch on Require single sign-on.
That passkey is your way back in. If your identity provider ever breaks, passkeys keep working when passwords don't.
WarningLocked out anyway — the passkey owner has left, or the device is gone? Contact InfraNest support. An administrator can restore password sign-in for you. It's recorded in your audit log and your owners are notified, so you'll always see that it happened.
Turn a connection off
- Open Settings → Sign-in.
- Find the connection and use its switch to stop people signing in with it. This is almost always what you want: it stops sign-ins straight away, keeps everyone's accounts linked to it, and can be switched back on later.
- To remove a connection entirely instead, use Remove — but note this unlinks everyone who signs in through it, and anyone who has only ever signed in this way has no password to fall back on.
Once anybody is signing in through a connection, InfraNest greys out the delete option and shows how many people are affected. Turn it off instead of trying to remove it.
If single sign-on is required and this is your only connection, InfraNest refuses to turn it off — turn off the requirement first.
Tips
- Register a passkey for at least one owner in Profile → Security before requiring single sign-on — it's your safety net if the identity provider ever breaks.
- Use the switch instead of removing a connection whenever possible; it's reversible and keeps accounts linked.
Troubleshooting
- Can't save a domain restriction: InfraNest blocks changes that would lock someone out while single sign-on is required. Check the list of affected people it shows you.
- Can't turn off a connection: if single sign-on is required and it's your only connection, turn off Require single sign-on first.
- Delete button greyed out: people are actively signing in through that connection. Turn it off instead — the row shows how many members are affected.
Was this article helpful?