As a System Admin, you control which sign-in methods are available to users on your plan. Smartsheet supports several authentication options, from basic email and password to enterprise single sign-on (SSO) providers. Activate or deactivate these options at the plan level or at the domain level, depending on how much control you need.
USM Content
Admin Center allows you to configure and manage authentication options for users in your organization at the plan or domain level.
- Plan-level: Authentication settings are applied to an entire Smartsheet plan (e.g., Business, Enterprise)
- Domain-level: Authentication settings are applied to specific email domains within a plan, allowing for more granular control over authentication and security
Which path applies to me?
How you manage authentication depends on whether you need plan-wide settings or domain-specific control.
- Plan level. If you want to set sign-in options for everyone on your plan, go to Manage plan-level authentication methods.
- Domain level. If you want to set sign-in options for specific email domains, go to Manage domain-level authentication methods.
Authentication options overview
Here's a quick look at the sign-in methods available at the plan level. Each method controls how users authenticate when they access Smartsheet.
| Option | Description | Learn more |
|---|---|---|
| Email + Password / One-time Password via Email | Users sign in with their Smartsheet email and password, or receive a one-time password (OTP) sent to their email. | Email-based TOTP overview |
| Users sign in with their Google account credentials. | — | |
| Microsoft Azure AD | Users sign in with their Microsoft Azure AD (Entra ID) credentials. | — |
| Apple | Users sign in with their Apple ID. | — |
| SAML | Users sign in through your organization's SAML-based identity provider (IdP), such as Okta, OneLogin, or Azure AD. Requires configuration. | Configure SAML SSO |
Enabling or disabling a sign-in method affects all users covered by that setting. Before deactivating a method, make sure affected users have at least one other active sign-in option.
Manage domain-level authentication methods
To modify how people in your domain sign in to Smartsheet:
- Sign in to Admin Center.
- Open the Menu icon in the upper left corner.
Navigate to Settings > Authentication.
The Authentication page displays.
Brandfolder Image
Select the method you want to use:
On the left panel
- SAML Identity Provider (IdP): Configure a SAML IdP and apply it to your organization's domain.
- One-time password via email: Enable an email-based TOTP login method for your organization's domains.
On the Authentication page
- Domain strict: Select domains from the list to activate domain strict. This will ensure that users within these domains only follow the login methods configured on the Authentication page.
- Fallback option for System Admins: Select domains from the list to activate a fallback option for System Admins.
Manage plan-level authentication methods
To modify how people in your plan sign in to Smartsheet:
The Admin Center homepage displays.
Scroll down to the Settings section and locate the Authentication card.
Brandfolder Image
Select the method you want to manage.
The Authentication window displays.
Brandfolder Image
- Use the checkboxes to activate or deactivate the available login options:
- Email + Password/One-time Password via Email
- MFA
- Microsoft Azure AD
- Apple
- SAML *
Fallback login option for System Admins
- Email + Password/One-time Password via Email
- Keep Email + Password/One-time Password via Email for Sys Admins (fallback)
- MFA
- Keep Email + Password/One-time Password via Email for Sys Admins (fallback)
- Select Save.
Select edit configuration to modify existing plan-level SAML configurations. If you haven't configured one, a not configured button displays.