How sign-in chooses a method

How the sign-in page decides between a password and your company's single sign-on, and how to exempt a person.

For: Administrators (the admin ability) · Last updated

People do not choose between a password and single sign-on. They type their email on the sign-in page and select Continue; the application then picks the method. The person's side of this is described in Signing in.

The decision#

For the email address entered:

  1. If the person is marked Local (non-SSO) account, the page asks for a password.
  2. Otherwise, if the address's domain has a Verified single sign-on configuration, the page offers Continue to your company's sign-in.
  3. Otherwise the page asks for a password.

A domain that is configured but Not verified does not route anyone to SSO. See Set up single sign-on.

The response never reveals whether an email belongs to a person, so the same rules apply to an address that is not on your Team page.

Exempt a person from single sign-on#

Some people need a password even though their domain uses SSO, for example a break-glass administrator or a contractor whose account is not in your identity provider. Tick Local (non-SSO) account (?) for them, either when you invite them or on their row at Settings → Administration → Team. The checkbox appears only for email addresses on a domain with verified SSO. The tooltip reads "Lets this person sign in with a password even if their email's domain requires single sign-on."

An exempt person needs a password. Invite them as usual so that they can set one; see Inviting people. Clear the checkbox and select Save to send them back to your company's sign-in page.

Limits on sign-in attempts#

The sign-in page limits how often one network address can check an email (20 times a minute) or try a password (5 times a minute). Past the limit, the person has to wait about a minute. A failed password attempt shows "Sign-in failed. Check your email and password." without saying whether the email or the password was wrong, and the same message appears when the limit is reached. A successful sign-in resets the password limit.

Revoked people#

Revoking a person ends their sessions and blocks both password and single sign-on sign-in. See Managing people.