Admin Center: Configure Require work accounts with SSO

Require work accounts with SSO enhances security for external sharing by requiring your external collaborators to sign in with single sign-on (SSO) to gain access to any content that you share with them.

Who can use this?

Plans:

  • Enterprise

Permissions:

  • System Admin

Find out if this capability is included in Smartsheet Regions or Smartsheet Gov.

Require work accounts with SSO is a plan-level policy that ensures access to Smartsheet is limited to users who have corporate-authenticated logins (SSO), thereby reducing the risk of unauthorized access. Learn more about governance policies for external collaborators.

Supported methods

  • Entra ID work account
  • Google work account (ISP domains, i.e., non-work accounts don't work)
  • SAML SSO

To use a SAML 2.0 compliant IdP, the external collaborator must be part of an Enterprise plan that has configured a SAML 2.0 Identity Provider for authentication into Smartsheet.


Configure the policy

To activate the Require work accounts with SSO policy:

  1. Sign in to Admin Center.
  2. Select the menu icon and navigate to Settings > Secure External Access.
  3. Slide the Require work accounts with single sign-on (SSO) toggle to turn on the policy.

    This policy applies to users who aren't part of any validated domain in the plan that enabled the policy, or any domain/email address mentioned in the Exempt list for these policies.

Workspace Admins

Workspace Admins can't set up the plan-level Require work accounts with SSO policy. The configuration is required by a System Admin.