Skip to main content

Enforcing Single Sign-On (SSO) methods

Enterprise teams can claim a domain and enforce Google, Apple, or Microsoft SSO for all users signing up with a specified domain email address.

Enforcing Single Sign-On (SSO) requires teammates using an email address associated with a verified domain to authenticate using the selected SSO provider.

How to enforce single sign-on (SSO)

1. Verify your domain

  1. Click on Settings in the sidebar and navigate to Team Settings, then select the Domain Verification tab.

    Descriptive text
  2. Click the + Add domain button and enter the domain you want to verify.

    Descriptive text
  3. Louper will generate TXT records for your domain. Add these TXT records to your domain’s DNS settings.

    Descriptive text
  4. After adding the records, return to the Domain Verification tab and click Verify. Once verification is complete, the domain status will be marked as verified.

    Descriptive text

2. Enable SSO enforcement

  1. After your domain is verified, click the Enforce SSO button.

    Descriptive text
  2. Select the SSO method you want to require for users with email addresses matching the verified domain.

    Click Enable enforcement.

    Descriptive text

All users with an email addresses under the verified domain will be required to sign in or sign up using the selected SSO method.

Notes

  • DNS changes may take up to 48 hours to fully propagate, depending on your domain provider and TTL settings.
  • Once SSO enforcement is enabled, all users with matching domain email addresses must authenticate using the selected SSO provider.
  • Only Team Owners and Admins can configure and enforce SSO.