Require users to sign in to a workspace with single sign-on (SSO), and let named people or whole domains keep password sign-in.
ℹ️ Role required: Site Admin or Admin. An Admin can set this for their own workspace only.
✅ Before you start: SSO must be set up on your site and at least one sign-in method must be turned on. See Single Sign-on (SSO) and 2FA/MFA (multi-factor authentication).
Open the authentication settings
- Go to Setup → Site settings.
- Select Authentication.
The requirement is set for one workspace at a time. If you look after several workspaces, go to Setup → Workspaces and click Access and edit on the one you want. Then follow the two steps above.
Choose who must use SSO
Under SSO requirement, pick one option:
- Optional: users choose single sign-on or password sign-in.
- Everyone: everyone must sign in with SSO, unless they are listed as an exception.
- Specific users: only the email addresses and domains you list under Required for must sign in with SSO.
An information box under the options tells you what your choice does, and whether it applies to your own account.
The Password row under Sign-in methods changes to Restricted as soon as you pick Everyone or Specific users. This is a preview of your choice. Nothing changes for your users until you save.
Add a rule or an exception
Choose Specific users to see the Required for list. The Exceptions list appears whenever the requirement is Everyone or Specific users.
- Click Add rule or Add exception.
- Choose Email or Domain.
- Enter the email address or the domain name, for example example.com.
- Click Add.
Each list shows the Type, Value and the date it was Added. Use the bin icon to remove a rule.
ℹ️ Note: An exception always wins. Domains match exactly, so example.com does not cover mail.example.com.
Save your changes
- Click Save changes. Sign-in methods, the requirement and both lists are saved together.
- If you are switching SSO on, read the Enforce single sign-on? message and check your exceptions.
- Click Enforce SSO.
You'll see the confirmation Authentication settings saved.
⚠️ Important: If your own account falls inside the requirement, Form offers to Add me as an exception before enforcing. Leave this ticked unless you can sign in with SSO yourself. Site Admins keep password sign-in across their organisation, so they never see this offer.
Click Cancel at any point to drop every unsaved change. If you leave the page with unsaved changes, Form asks whether to discard them.
Something not working?
No SSO requirement section? Turn on a single sign-on method under Sign-in methods first. If there are no methods to turn on, contact Me Learning to add SSO to your site.
"This rule is already in the list"? The same value is already saved. A value cannot be a requirement and an exception at the same time.
"Another administrator saved this policy first"? Someone else saved while you were editing. Form loads their version and drops your unsaved changes. Review the settings and make your changes again.