How sign-in chooses a method
How the sign-in page decides between a password and your company's single sign-on, and how to exempt a person.
People do not choose between a password and single sign-on. They type their email on the sign-in page and select Continue; the application then picks the method. The person's side of this is described in Signing in.
The decision#
For the email address entered:
- If the person is marked Local (non-SSO) account, the page asks for a password.
- Otherwise, if the address's domain has a Verified single sign-on configuration, the page offers Continue to your company's sign-in.
- Otherwise the page asks for a password.
A domain that is configured but Not verified does not route anyone to SSO. See Set up single sign-on.
The response never reveals whether an email belongs to a person, so the same rules apply to an address that is not on your Team page.
Exempt a person from single sign-on#
Some people need a password even though their domain uses SSO, for example a break-glass administrator or a contractor whose account is not in your identity provider. Tick Local (non-SSO) account (?) for them, either when you invite them or on their row at Settings → Administration → Team. The checkbox appears only for email addresses on a domain with verified SSO. The tooltip reads "Lets this person sign in with a password even if their email's domain requires single sign-on."
An exempt person needs a password. Invite them as usual so that they can set one; see Inviting people. Clear the checkbox and select Save to send them back to your company's sign-in page.
Limits on sign-in attempts#
The sign-in page limits how often one network address can check an email (20 times a minute) or try a password (5 times a minute). Past the limit, the person has to wait about a minute. A failed password attempt shows "Sign-in failed. Check your email and password." without saying whether the email or the password was wrong, and the same message appears when the limit is reached. A successful sign-in resets the password limit.
Revoked people#
Revoking a person ends their sessions and blocks both password and single sign-on sign-in. See Managing people.