RRecords Labs Help Center

SSO and passkeys

How people prove who they are is set in two places: Settings → Security for the organization, and My Account → Security for each person. Open Account settings from your profile menu to reach My Account.

  • Two-factor sign-in and passkeys are available on every plan.

  • Single sign-on (SAML) is included on Operate and above.

  • SCIM provisioning is included on Scale and above.

If a feature is not in your plan, the setup action returns a message saying so.

Two-factor sign-in

Every member can add a second factor, and owners and admins are required to.

  1. Open My Account → Security.

  2. Next to Two-factor authentication, choose Set up (or Manage if you already have one).

  3. Choose Add authenticator.

  4. Scan the QR code with Google Authenticator, Microsoft Authenticator, 1Password, or any similar app. If you cannot scan, use the manual setup key.

  5. Enter the six-digit Verification code and choose Verify.

Devices you choose to trust at sign-in appear under Trusted devices in the same panel, where you can revoke any of them.

Admins see the same control under Settings → Security → Sign-in → Two-factor authentication, and can filter the People list by MFA required to see who still needs to enroll.

Passkeys

A passkey lets you sign in with Face ID, Touch ID, Windows Hello, or a hardware security key instead of a password.

For the organization (admins): Settings → Security → Sign-in has a Passkeys card with the switch Allow passkey sign-in. It is on by default. Turning it off stops passkey sign-in for everyone, including passkeys already created.

For yourself:

  1. Open My Account → Security.

  2. In the Passkeys section, choose Create passkey and follow your device's prompt.

  3. Give it a name so you can tell devices apart. You can rename or delete it later.

On the sign-in page, choose Sign in with a passkey and approve on your device. A passkey is a sign-in method, not a second factor: if your role requires two-factor sign-in, you still complete it after a passkey sign-in.

Single sign-on (SAML)

With SSO, people with an email address on your domain sign in through your identity provider: Okta, Microsoft Entra, or any SAML 2.0 provider. New members are created automatically on their first sign-in.

Set it up

  1. Go to Settings → Security → Single sign-on.

  2. On the Single sign-on (SAML) card, choose Set up SSO.

  3. Enter your Email domains, comma separated.

  4. Provide the IdP metadata: paste a Metadata URL or choose Paste XML and paste the metadata document from your provider.

  5. Pick the Role for new members. This is what first-time SSO sign-ins receive.

  6. Choose Register identity provider.

  7. The card now shows the values your IdP needs: the ACS URL and Entity ID. Copy them into the SAML app in your provider.

Use Edit to change domains, metadata, or the role. Use the SSO enabled switch to turn the connection on or off: while it is off, the sign-in page stops sending those domains to your identity provider and asks for a password instead. The trash icon removes the connection after you confirm. Before you turn SSO off, keep in mind that members whose accounts were already linked to SSO (see below) no longer have a working password.

What happens to existing members

If a member already has a password account with the same email, their first SSO sign-in links that account rather than creating a new one. Their role and settings are kept. After linking, password sign-in no longer works for that person; SSO is their sign-in from then on. A deactivated member is never reactivated by SSO.

SSO and two-factor sign-in

An SSO session is exempt from the app's two-factor requirement. Your identity provider owns that policy. In Okta, for example, the app sign-on policy can require a second factor before the first assertion is sent.

SCIM provisioning

SCIM lets your identity provider create, update, and deactivate members directly, so offboarding happens when IT removes someone. Directory groups sync to Teams.

  1. Go to Settings → Security → Single sign-on.

  2. On the SCIM provisioning card, copy the SCIM base URL into your provider's SCIM settings.

  3. Pick the Role for provisioned members. If you leave it at Member, provisioned members get your organization's Default role for new members (Settings → Roles & Permissions) instead.

  4. Choose Generate token. The token is shown once; copy it into your provider as the bearer token.

Turn off the Provisioning switch to pause without changing the token. Rotate token replaces the token right away, so update your provider with the new one. Revoke stops provisioning; members already synced are not removed.

Was this article helpful?
Related articles
GuestsTeam & accessAPI changelogDevelopersAuthentication, keys and scopesDevelopersBrowser extensionDevelopers