> ## Documentation Index
> Fetch the complete documentation index at: https://docs.dovetail.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication settings

<img src="https://mintcdn.com/dovetail-e5aa4160/vcUElSHXqx5sPZFV/help/authentication-settings/authentication-settings-hero.png?fit=max&auto=format&n=vcUElSHXqx5sPZFV&q=85&s=9401616b3276cbdf2ba87cd900868977" alt="Authentication Settings Hero Pn" width="2184" height="1452" data-path="help/authentication-settings/authentication-settings-hero.png" />

<Info>
  Only **workspace admins** can adjust these settings on the following plans:

  * Current Business and Enterprise
  * Legacy Business and Enterprise
  * Legacy Professional

  If there is a diamond on the Authentication tab, you are on a plan that does not support this feature.
</Info>

## Overview

Workspace admins can streamline and manage user authentication to Dovetail. Use [Authentication settings](https://dovetail.com/settings/authentication) to set allowed email domains, enable automatic account creation, choose what methods users can use to sign up, and log in to the workspace.

***

## Set allowed email domains

Admins can set allowed email domains for your workspace so that they can be used for automating user provisioning. If there is a diamond on the Authentication tab, you are on a plan that does not support this feature.

* To do this, ⚙️ [Settings → Authentication](https://dovetail.com/settings/authentication), and enter your allowed email domain under Domains. Please note that you can only add the domain name of the email address you currently have in your email address to log into the workspace.
* Once entered, this will be automatically saved and applied to your workspace.

<img src="https://mintcdn.com/dovetail-e5aa4160/vcUElSHXqx5sPZFV/help/authentication-settings/emails.png?fit=max&auto=format&n=vcUElSHXqx5sPZFV&q=85&s=4ad114e1610a987d542ae5823dee5907" alt="Emails Pn" width="3869" height="821" data-path="help/authentication-settings/emails.png" />

<Info>
  If you are trying to add a separate email domain to your own, please have a workspace admin reach out to [support@dovetail.com](mailto:support@dovetail.com), and our team will be happy to help. If you are chatting via the app messenger, request to speak to our support team, and Fin, our AI agent, can route you to the team.
</Info>

***

## Automatic account creation

Enable automatic account creation to allow your colleagues who share an email domain with one of your allowed email domains to join your workspace as a viewer, without needing an invite.

<Info>
  Please note that:

  * Viewers are only available on select legacy plans and our Enterprise plan.
  * Automatic account creation is *enabled* by default.
  * Managing automatic account creation is only available on Professional (***legacy***), Business, and Enterprise plans
</Info>

<video autoPlay={true} muted={true} loop={true} playsInline={true} className="w-full" src="https://videos.ctfassets.net/8fl1jrx919na/6lPzjhZVlLbQy8iC8rrGaF/0aebac87e6971dfbb70f718b31dcb4e7/Allowed_domains_viewers.mp4" />

***

## Authentication options

<Info>
  Available on **Business** and [Enterprise plans](https://dovetail.com/pricing/)
</Info>

Allow your users to log in or sign up using various authentication options by enabling and disabling options to your desired configuration. [Learn how to streamline authentication to Dovetail →](https://dovetail.com/academy/streamline-authentication-to-dovetail/)

By default, users can sign up and log in to a workspace with:

* **Password**: Use an email address and create a password to log in.
* **Google**: Use your Google account email and password to sign up and log in to Dovetail.
* **Microsoft**: Use your Microsoft account email and password to sign up and log in to Dovetail.

Business and Enterprise workspaces have an additional authentication method available: **SSO**. Only Business and Enterprise plans can manage authentication methods — for example, restricting sign-up and login to SSO only. To enforce this, a workspace admin can go to ⚙️ [Settings → Authentication](https://dovetail.com/settings/authentication)  → **Authentication connections.**

<img src="https://mintcdn.com/dovetail-e5aa4160/vcUElSHXqx5sPZFV/help/authentication-settings/authentication.png?fit=max&auto=format&n=vcUElSHXqx5sPZFV&q=85&s=d555d07ac680d7e632e5843ee93ce862" alt="Authentication Pn" width="2086" height="544" data-path="help/authentication-settings/authentication.png" />

***

## Single sign-on (SSO) settings

<Info>
  Available on **Business** and [Enterprise plans](https://dovetail.com/pricing/)
</Info>

Enable SSO to allow your users to sign in to your workspace with ease. Configuring, validating, and maintaining SSO is your organization’s responsibility and is typically handled by your IT team. While Dovetail provides documentation and in-product guidance, we’re not able to configure or troubleshoot SSO on your behalf.A workspace Admin is required to set up and manage SSO in Dovetail. We recommend inviting your IT administrator into your Dovetail workspace and granting them Admin access so they can properly configure and maintain your SSO connection.

Our SSO experience is powered by Auth0 and designed to make setup as simple as possible. When creating an SSO enterprise connection, Dovetail automatically provides step-by-step instructions tailored to your selected identity provider. [Learn how to configure SSO for your workspace →](https://dovetail.com/help/configure-single-sign-on-sso/)

<img src="https://mintcdn.com/dovetail-e5aa4160/vcUElSHXqx5sPZFV/help/authentication-settings/sso.png?fit=max&auto=format&n=vcUElSHXqx5sPZFV&q=85&s=c106e4942d030b0fb764e7d7b7dccb29" alt="Sso Pn" width="1978" height="1332" data-path="help/authentication-settings/sso.png" />

***

## SCIM provisioning

<Info>
  Available on **Business** and [Enterprise plans](https://dovetail.com/pricing/)
</Info>

Automatically provision, manage, and deactivate users by enabling SCIM provisioning. [Learn how to configure SCIM for your workspace →](https://dovetail.com/help/scim-overview/)

***

## Two-factor authentication

<Info>
  Available on all plans
</Info>

When enabled, you’ll verify your identity using an authenticator app each time you sign in, protecting your account even if your password is compromised. [Learn how to configure two-factor authentication for your workspace →](https://docs.dovetail.com/help/two-factor-authentication)
