Activate strict domain-level sign-in

Enforce specific domain-level sign-in methods for your validated and activated domains.

Who can use this?

Plans:

  • Enterprise

Permissions:

  • System Admin

Find out if this capability is included in Smartsheet Regions or Smartsheet Gov.

How does strict domain-level sign-in work?

If you've set up a domain-level sign-in policy, you can make specific domain-level sign-in methods mandatory for all users within your activated domains. Users in these domains across Smartsheet plans can only use domain-level sign-in methods enabled on the Authentication page in Admin Center.


What determines which sign-in options users see?

The sign-in options Smartsheet presents to users depend on which policies are active and whether domain strict is enabled. The following table describes each configuration state.

 

Configuration

Sign-in options applied

Domain strict is on

Domain-level policy only. Plan-level policies don't apply.

Domain strict is off

Options from the domain-level and plan-level policies are combined.

No domain policy configured

Plan-level policy only.

No policies configured

Default Smartsheet sign-in options.


What happens when domain strict is off?

When domain strict is off and both a domain policy and a plan policy are active, Smartsheet merges the available sign-in options from both. If the same authentication method appears in both policies, it appears once in the combined result, sourced from the domain-level policy.

For example, if a plan-level policy includes Google, SAML, and Azure, and the domain-level policy includes SAML and TOTP, users see the following options when domain strict is off.

 

 

Authentication options

Plan-level policy

Google, SAML, Azure

Domain-level policy

SAML, TOTP

Presented to users

Google, Azure, TOTP, SAML

In this example, SAML appears in both policies. The domain-level version is used and appears once.


How does domain policy affect new user sign-up?

When a new user's email domain matches an active domain policy, Smartsheet presents that domain policy's authentication options during sign-up.

Activating strict domain-level sign-in impacts all users in the associated domains. Before enabling it, notify all Smartsheet users within those domains about this change.


Before you begin

Before you activate strict domain-level sign-in, complete the following steps:

Once domain strict is active, users within impacted domains can't sign in through plan-level sign-in methods. 


Activate strict domain-level sign-in

  1. Sign in to Admin Center and select the Menu icon to open the left panel.
  2. Navigate to Settings > Authentication.
  3. Select the domains for which you want to implement strict domain-level sign-in from the dropdown menu. 

    Brandfolder Image
    Activate strict domain-level login