Enforce specific domain-level sign-in methods for your validated and activated domains.
USM Content
How does strict domain-level sign-in work?
If you've set up a domain-level sign-in policy, you can make specific domain-level sign-in methods mandatory for all users within your activated domains. Users in these domains across Smartsheet plans can only use domain-level sign-in methods enabled on the Authentication page in Admin Center.
What determines which sign-in options users see?
The sign-in options Smartsheet presents to users depend on which policies are active and whether domain strict is enabled. The following table describes each configuration state.
Configuration | Sign-in options applied |
|---|---|
Domain strict is on | Domain-level policy only. Plan-level policies don't apply. |
Domain strict is off | Options from the domain-level and plan-level policies are combined. |
No domain policy configured | Plan-level policy only. |
No policies configured | Default Smartsheet sign-in options. |
What happens when domain strict is off?
When domain strict is off and both a domain policy and a plan policy are active, Smartsheet merges the available sign-in options from both. If the same authentication method appears in both policies, it appears once in the combined result, sourced from the domain-level policy.
For example, if a plan-level policy includes Google, SAML, and Azure, and the domain-level policy includes SAML and TOTP, users see the following options when domain strict is off.
Authentication options | |
|---|---|
Plan-level policy | Google, SAML, Azure |
Domain-level policy | SAML, TOTP |
Presented to users | Google, Azure, TOTP, SAML |
In this example, SAML appears in both policies. The domain-level version is used and appears once.
How does domain policy affect new user sign-up?
When a new user's email domain matches an active domain policy, Smartsheet presents that domain policy's authentication options during sign-up.
Activating strict domain-level sign-in impacts all users in the associated domains. Before enabling it, notify all Smartsheet users within those domains about this change.
Before you begin
Before you activate strict domain-level sign-in, complete the following steps:
- Set up at least one domain-level policy.
- Activate and validate your domain.
- Notify all Smartsheet users in the affected domains about this change.
Once domain strict is active, users within impacted domains can't sign in through plan-level sign-in methods.
Activate strict domain-level sign-in
- Sign in to Admin Center and select the Menu icon to open the left panel.
- Navigate to Settings > Authentication.
Select the domains for which you want to implement strict domain-level sign-in from the dropdown menu.
Brandfolder Image