> ## Documentation Index
> Fetch the complete documentation index at: https://docs.salesfinity.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Secure sign-in with SSO and two-factor

> Turn on two-factor for yourself, and require single sign-on or MFA for your whole team.

Keep your team's calls, contacts and CRM access behind a sign-in your company controls.
You can protect your own account in a minute, and admins can require the same of everyone.

## Ways to sign in

Everyone can sign in to Salesfinity with:

* **Google**
* **Microsoft**
* **Okta**
* An email and password

Single sign-on (SSO) means using Google, Microsoft or Okta instead of a Salesfinity password.

## Turn on two-factor for yourself

<Steps>
  <Step title="Open Settings › Login & Security">
    Your password and any **Linked accounts** show under **Login**.
  </Step>

  <Step title="Set up an authenticator app">
    Under **Two-factor authentication (2FA)**, set up **Authenticator App** and scan the code with
    your authenticator app.
  </Step>

  <Step title="Sign in with the second step">
    From now on, after your password, Salesfinity asks for the code from your app.
  </Step>
</Steps>

## Require SSO or MFA for your team

Owners and admins can make sign-in rules for everyone on the team. Open **Settings** › **Team** and
find **Security**.

| Setting | What it does |
| - | - |
| **Enforce Multi-Factor Authentication** | Asks every member who has not set up two-factor to turn it on. |
| **Enforce Single Sign-On** | Asks every member who signed in with a password to sign out and sign back in with Google, Microsoft or Okta. |

### What your team sees

<Steps>
  <Step title="A one-week heads-up">
    When you turn a rule on, members who do not meet it see a notice with the date it takes effect,
    one week later. They can choose **Remind Me Later** until then.
  </Step>

  <Step title="The rule takes effect">
    After that date the notice can no longer be dismissed. For SSO, the member must sign out and
    sign back in with Google, Microsoft or Okta. For MFA, they must set up two-factor to continue.
  </Step>
</Steps>

<Warning>
  Before you enforce SSO, check that every rep can sign in with Google, Microsoft or Okta using
  the same email address they use in Salesfinity. Anyone who cannot will be locked out once the
  week is up.
</Warning>

Members can see which rules their team enforces, but only owners and admins can switch them.

## Next steps

<CardGroup cols={2}>
  <Card title="Invite your team" icon="user-plus" href="/account/seats-and-roles">
    Bring in reps and give each one the right seat.
  </Card>

  <Card title="Set up your team" icon="sliders" href="/account/team-settings">
    Name your team, set notifications and dialer rules.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.