Security, 2FA & SSO
Two-factor, your devices, single sign-on and the IP allowlist.
Your own security
Settings → Security is where you change your password, set up two-factor, and see where you're signed in.
- Two-factor enrolment shows a QR code to scan with your authenticator app; the manual key is behind a disclosure if you need it.
- Devices groups your sessions by device, with the last sign-in and how many sessions it holds. Revoking clears that whole device, not one session at a time.
Workspace security
Org settings → Security & SSO:
| Control | What it does | Plan |
|---|---|---|
| Require 2FA | Everyone in the workspace must set up two-factor. | Business |
| IP allowlist | Restrict access to known networks. | Business |
| Domain-based join | Let people on your email domain join, with or without approval. | Team |
| SSO / SAML | Sign in through your identity provider. | Enterprise |
| SCIM provisioning | Create and deactivate accounts from your directory. | Enterprise |
Before you turn on Require 2FA
Members without two-factor set up are prompted to add it before they can continue. Give the team a heads-up so nobody is stuck mid-task without their phone.
Data
Org settings → Data & Compliance holds your retention settings and the data-usage consent controls, and Trash holds anything deleted, recoverable until it's purged.
Still stuck? Open a support ticket and we'll help you out — tracked right inside Noots.
