Let your team sign in with Google, GitHub or Microsoft instead of a password, and control the rules around it — for organization owners and admins.
Overview
- A sign-in connection is your organization's policy for a given provider: which email domains it accepts and what happens when someone new signs in with it.
- Once a connection is added, anyone in your organization can use that provider right away.
- You can restrict connections to your own email domains, and even require single sign-on for everyone.
Add a sign-in connection
- Go to Settings → Sign-in.
- Under Sign-in connections, choose a provider to add.
- The connection is on straight away — anyone in your organization can now use that provider.
NoteIf a provider isn't offered, it hasn't been set up for the platform yet. Ask your InfraNest administrator.
Limit sign-in to your own email domains
By default, a connection accepts any email address. To narrow it down:
- Open the connection you want to restrict.
- Either type the domains you want to allow into Allowed email domains, one per line, or switch on Use our verified domains to automatically follow the domains you've already verified.
- Check the row — it always shows what the restriction currently accepts.
Two things to know:
- Subdomains are not included. Allowing
acme.comdoes not allowmail.acme.com. Add it separately if you need it. - Turning on "Use our verified domains" before you've verified any accepts everything. The row will say so when this happens.
Members who can't use any of your connections are protected: if a restriction would lock somebody out while single sign-on is required, InfraNest refuses to save it and tells you who's affected.
Require single sign-on
Switching on Require single sign-on turns off password sign-in for everyone in the organization.
Before you can enable it, InfraNest checks that nobody gets stranded:
- Every member must be able to use one of your connections.
- At least one owner must have a passkey registered.
That passkey is your way back in — if your identity provider ever breaks, passkeys keep working when passwords don't. Register one in Profile → Security first.
WarningLocked out anyway — the passkey owner has left, or the device is gone? Contact InfraNest support. An administrator can restore password sign-in for you. This is recorded in your audit log and your owners are notified, so you'll always see that it happened.
Turn a connection off
- Find the connection you want to change.
- Use its switch to stop people signing in with it, or remove it entirely.
If single sign-on is required and it's your only connection, InfraNest refuses to turn it off — turn off the requirement first.
Tips
- Signing in with a provider never changes anybody's role or permissions.
- Every change here is written to your Audit Log.
- Passkeys keep working while single sign-on is required — that's deliberate, so keep at least one owner's passkey up to date.
Was this article helpful?