Forcing SSO-only sign-in for your workspace
Block password sign-in once SSO is verified working.
Updated
Once your SSO connection is set up and tested, you can require all members to sign in via SSO β passwords stop being accepted.
How to enforce
- Open Settings β SSO.
- Toggle Require SSO for sign-in.
- Confirm.
From that moment on, password sign-in is blocked for users matching your verified domain. They're redirected to your IdP.
What about Owners?
Owners are exempt by default β so a misconfigured SSO can never lock you out of your own workspace. You can opt in by checking Apply to Owners too.
Test SSO thoroughly first
Before enforcing, sign in as a non-Owner test user via SSO end-to-end. If anything's broken, you don't want to find out by losing access to your workspace.
Disabling enforcement
Same toggle, off. Password sign-in works again for everyone immediately.
Was this article helpful?
Your feedback helps us improve our docs.

