Security, 2FA & SSO

Two-factor, your devices, single sign-on and the IP allowlist.


Your own security

Settings → Security is where you change your password, set up two-factor, and see where you're signed in.

  • Two-factor enrolment shows a QR code to scan with your authenticator app; the manual key is behind a disclosure if you need it.
  • Devices groups your sessions by device, with the last sign-in and how many sessions it holds. Revoking clears that whole device, not one session at a time.

Workspace security

Org settings → Security & SSO:

ControlWhat it doesPlan
Require 2FAEveryone in the workspace must set up two-factor.Business
IP allowlistRestrict access to known networks.Business
Domain-based joinLet people on your email domain join, with or without approval.Team
SSO / SAMLSign in through your identity provider.Enterprise
SCIM provisioningCreate and deactivate accounts from your directory.Enterprise
Before you turn on Require 2FA

Members without two-factor set up are prompted to add it before they can continue. Give the team a heads-up so nobody is stuck mid-task without their phone.

Data

Org settings → Data & Compliance holds your retention settings and the data-usage consent controls, and Trash holds anything deleted, recoverable until it's purged.

Still stuck? Open a support ticket and we'll help you out — tracked right inside Noots.