Enterprise sign-in

Verify the domain first, then set up the connection — and what an admin may operate.

Under Settings → „Sicherheit & SSO“ (Security & SSO) a workspace signs in through its own identity provider (SAML 2.0).

Owners and admins may read it. Every other role gets a "not found" page.

The page opens with „Zwei-Faktor-Authentifizierung“ (Two-factor authentication), which applies to every workspace and is described under Two-factor requirement. Below it come the three SSO cards, in the order you need them: „E-Mail-Domains“, „Unternehmens-Anmeldung (SSO)“ (Enterprise sign-in), „Anmeldeadresse für diesen Arbeitsbereich“ (Sign-in address for this workspace).

The signed-in product speaks German, so its labels are quoted in German throughout, with the English rendering in italics.

Step 1: Verify the domain

Add the domain. The page then shows you a TXT record with copy buttons:

  • Name: _verstag-challenge.YOUR-DOMAIN
  • Value: verstag-domain-verification=TOKEN — the token is 64 hexadecimal characters

Create the record in DNS, then press „Prüfen“ (Check). There is no automatic re-check: verification happens only when you press it.

The window is 14 days. If it expires without the record being found, you reissue the verification with „Nachweis neu ausstellen“ (Reissue verification) — and that gives you a new token, so the old DNS record becomes worthless.

An expired verification is not granted even if the record is now in DNS. Reissue it in that case and enter the new value.

A verified domain is withdrawn as soon as a check no longer finds the record. The same 14-day window then opens again — this time with the same token, so the record only has to go back.

Step 2: Set up the connection

Without a verified domain the connection card shows no form, only the sentence naming verification as the first step. Only afterwards can you enter the identity provider, pick the role for new members and switch automatic admission on.

An already active connection can be pointed at a different provider without re-verifying — after a certificate change, for instance.

When the sign-in expires

With the sign-in requirement switched on, a sign-in through the identity provider stands for at most twelve hours; after that the workspace has it confirmed again.

When the window expires you land at your workspace's sign-in address with a sentence saying "expired". Signing in through the provider again is enough.

Without the sign-in requirement switched on, none of this applies.

When somebody should lose access

If somebody is blocked at the identity provider, a new sign-in becomes impossible at once. A running session ends only when the twelve-hour window expires.

Where access should end immediately, deactivate the membership in the workspace. Whoever is deactivated does not get back in through the provider either.

What an admin may operate

An admin sees the connection as four state rows — „Identitätsanbieter“ (Identity provider), „Rolle für neue Mitglieder“ (Role for new members), „Automatische Aufnahme“ (Automatic admission), „Verbindung“ (Connection) — and in the domain section the list, the status, the TXT record with its value, and the copy buttons.

What they may not operate: saving the connection, and in the domain section „Prüfen“, reissuing a verification and adding a domain. Where the form would be, they get a sentence saying who may.

An admin may operate the switch for the sign-in requirement. So they get exactly one of the card's two switches.

When the plan does not include it

A sentence naming the plan stands in place of the form. Where a workspace loses the capability, the page says it differently from never having had it: existing sign-ins keep working.