Specset
Organization

Organization security

On this page

Organization administrators set sign-in requirements under Org Settings → Security & SSO. These settings control access to the selected organization. Personal passwords, passkeys, and recovery options belong in Account security.

Choose an SSO policy

Under Authentication, set Single sign-on (SSO):

  • Not allowed: Use the permitted password or passkey methods.
  • Optional: Use a configured SSO provider or permitted password or passkey methods.
  • Required: Use an identity provider configured for this organization. A native passkey or password alone does not replace SSO.

Connect a provider before choosing Required. See Single sign-on for Google Workspace, Okta, and Microsoft Entra ID setup.

Set the authentication requirement

The Authentication requirement is separate from the SSO policy:

  • MFA optional: No additional organization-wide MFA requirement. A member's stronger account requirements still apply.
  • MFA required: A permitted sign-in that satisfies multi-factor authentication, such as a passkey or qualifying SSO.
  • Phishing-resistant MFA required: An approved passkey or SSO that Specset can verify meets this requirement. If SSO is also required, members must use qualifying SSO.

Connecting an SSO provider is not by itself proof of MFA or phishing resistance. Work with Specset support to confirm the provider's supported verification and policy before enforcing a stronger requirement. Authenticator-app codes do not satisfy phishing resistance.

Choose password and passkey methods

When SSO is Not allowed or Optional, the Sign-in methods section lets you permit Passwords and Passkeys. Allowing a method does not override the authentication requirement. For example, a password alone cannot satisfy MFA required.

Authenticator app codes is a permission setting for a second step after a password. Authenticator-app setup is not yet available in production, so do not depend on it as your team's only MFA route.

Save or discard changes

  1. Configure the authentication, onboarding, and session settings you want.
  2. Click Save at the top of the page.
  3. If prompted, complete Verify to save changes with a method that meets the current and proposed requirements.
  4. Wait for the save to complete. Members who do not meet the saved policy will need to sign in through a qualifying route before continuing in the organization.

Click Discard to restore the saved settings. Cancelling a verification dialog keeps your draft available without applying it. If another administrator changes the policy while you are editing, refresh the settings and review your changes again.

Specset checks that the saving administrator has a usable route under the proposed policy. That check does not enroll every member for you. Test administrator access and prepare members before requiring SSO or stronger authentication. The form will not lower an existing phishing-resistant requirement.

Provider connections, edits, and removals are saved in their own dialogs, separately from the page draft. Open Specset in a browser for SSO verification if you are using the installed app.

Onboarding and session duration

Under Onboarding and sessions, choose Invite Only, Open Domain (Auto-join), or Manual Approval to control how people join. Domain-based onboarding depends on your configured, verified domains. See Team & roles.

Set Session duration (minutes) to control expiration for future sign-ins. Existing sessions keep their current expiration. Account-level security limits can require sign-in sooner.

New members must complete the selected organization's authentication requirements after account setup or invitation acceptance. If you intend to allow only passkeys without SSO, arrange account setup and approved passkey enrollment with Specset support first; that route does not offer self-service password signup.

Members of multiple organizations

Each organization checks its own sign-in requirements. Signing in to an organization that allows passwords does not grant access to another organization that requires SSO or phishing-resistant MFA. Members may be asked to verify again when switching organizations.

An organization's settings do not change the policy of another organization. Account-level protections can still apply across memberships, including during credential changes and recovery.