PRACTICAL GUIDE

People and security

Manage roles, MFA, recovery codes, company access rules, sessions and supported SSO connections.

STEP 01

Turn on authenticator MFA

Authenticator MFA adds a time-limited code after the password check.

  1. 1

    Open Security, start MFA enrolment and scan the QR code with a trusted authenticator application.

  2. 2

    Enter the current six-digit code to confirm the authenticator is working.

  3. 3

    Save the single-use recovery codes in a secure location separate from the device.

STEP 02

Recover or secure an account

Act quickly when a password, device or session may no longer be trusted.

  1. 1

    Use a saved recovery code when the authenticator is unavailable, or request a password reset from the sign-in page.

  2. 2

    Change the password and revoke other active sessions from Security.

  3. 3

    Generate a new recovery-code set after using or exposing an old code; the previous set becomes invalid.

STEP 03

Configure company SSO

Administrators can connect an OpenID Connect or SAML 2.0 identity provider for the company domain.

  1. 1

    Open Security, choose OpenID Connect or SAML 2.0, and register the displayed callback or ACS details with the identity provider.

  2. 2

    For OpenID Connect, enter the issuer, client ID and secret. For SAML, enter the IdP entity ID, SSO URL and X.509 signing certificate.

  3. 3

    Save the connection and test with a non-owner account before enforcing the new sign-in path for the wider team.

Keep in mindKeep one tested owner recovery path available while changing company-wide identity settings.