Governance policies for external collaborators

Require work accounts with SSO and Require MFA enhance security for external sharing by requiring your external collaborators to sign in with a single sign-on (SSO) and an additional layer of authentication (Require MFA) to gain access to any content that you share with them.

Who can use this?

Plans:

  • Enterprise

Permissions:

  • System Admin

Find out if this capability is included in Smartsheet Regions or Smartsheet Gov.

This article explains what these policies do, who they apply to, and how they behave across different access methods. For step-by-step configuration instructions, use the links in Get started below.

What's an external collaborator?

An external collaborator is a user who has been invited to collaborate on a sheet or workspace but whose email address doesn’t match the domains associated with the plan that owns the sheet or workspace and who isn’t a member of that plan.

Policy behavior and coverage

External collaborators accessing items that require SSO or MFA must sign in with their company account unless they’re on the exempt list. Smartsheet promps them to use their organization’s SSO login to verify their identity.

Consider the following

  • Require work accounts with SSO applies at the plan level.
  • Require MFA can apply to the account as a whole or to specific workspaces.
  • System Admins can allow workspace Admins to enable MFA for their workspaces.
  • External collaborators see a prompt to authenticate through their organization's identity provider (IdP), confirming their credentials remain active in their organization's directory.
  • An exempt list (also called the Trusted Domain list) allows System Admins to exclude specific domains or email addresses from these requirements.
  • You must complete a configuration process to enable your users to sign in to Smartsheet using SAML or SSO. This configuration can be done at the plan level for users on Enterprise plans or at the domain level for all users associated with a specific email domain
  • Once enabled, the Require work accounts with SSO and Require MFA policies apply exclusively to core items (sheets, reports, and dashboards) within the core Smartsheet application, excluding items within Smartsheet Premium apps
  • These policies apply to users who aren't part of any validated domain in the plan that enabled the policy, or any domain/email address mentioned in the Exempt list for these policies

API access for external collaborators

External collaborators who use public API calls to access shared Smartsheet items protected by Require work accounts with SSO or Require MFA can only gain access if their domain or email address is on the exempt list, or if it's a validated domain of the plan.

API access follows the same policy enforcement as browser access. If an external collaborator's domain or email isn't on the exempt list or a validated domain, their API calls to protected items fail.

If your external collaborators encounter issues accessing their shared items, they should reach out to the System Admin of the plan to which those items belong.


Get started

Use the articles below to set up and configure these policies:

  • Require work accounts with SSO: A plan-level policy that guarantees access to Smartsheet is restricted to users with corporate-authenticated login (SSO), thereby reducing the risk of potential unauthorized access
  • Require MFA: External collaborators are required to authenticate via Multi-Factor Authentication (MFA), enhancing their security with an additional layer of verification. Even if a password gets compromised, the MFA functionality can thwart unauthorized access
  • Exempt list: Allow System Admins to specify domains and individual email addresses exempt from the policies

Like the web and desktop apps, the Smartsheet mobile app honors any Secure External Access policies enabled in Admin Center.

FAQs

How do external collaborators without an organizational SSO account access shared items?

  • Exempt list: A System Admin can add the collaborator's email address or domain to the Exempt list, bypassing the SSO and MFA requirements for that user. 
  • Email-based MFA: External collaborators can receive an email-based code for verification if Require MFA is enabled, but they don't have an organizational SSO account.
  • Google or Microsoft SSO: If the collaborator has a Google or Microsoft account, they can use that as their corporate login.

Can any workspace Admin enable these policies?

Workspace Admins can enable the Require MFA policy at the workspace level, but only if a System Admin has first enabled the workspace-level Require MFA option. 

Workspace Admins can't configure the Require work accounts with SSO policy.