Skip to content
FirstSIDocs

Customer security and SSO

Allowed sign-in methods, mandatory two-factor authentication, company sign-in (Entra ID, Okta, Google, OIDC), sign-out after inactivity.

These settings live in Settings → Authentication, on the screen titled Tenant security configuration.

Sign-in methods

SettingDefaultValues
Email/password sign-inon
TOTP (authenticator app)offDisabled, Optional or Required
Security keys (WebAuthn)offDisabled, Optional or Required
Require at least one 2FA methodno
Enterprise SSOno

There must always be at least one way to sign in, local or SSO. If you make SSO mandatory, local sign-in has to be turned off.

What "Mandatory" changes

A user who hasn't set up the required method yet is blocked at their next sign-in: they can't do anything in the console until it's in place. They are sent to Settings → Security, with a banner, Two-factor authentication required by your organisation, telling them what to do. Sessions opened through SSO are not affected, since the identity provider already handles the second factor.

Before switching to Mandatory, look at the Two-factor column in Settings → Users to see who will be blocked, and warn the people concerned.

Company sign-in (SSO)

Supported providers: Microsoft Entra ID (Azure AD), Okta, Google Workspace, and any OAuth2 / OpenID Connect provider.

  1. At the provider, create a web application and register the callback URL shown by FirstSI as its redirect address.
  2. In FirstSI, enter the Client ID and Client Secret. Leave the secret empty if you don't want to change the one already stored.
  3. In Allowed domains, put your email domains. Left empty, the field accepts every domain.
  4. Tick Automatic user creation if an unknown person coming through SSO should get an account (read-only). Otherwise, create accounts in advance.

The SSO sign-in button then appears on the sign-in screen as soon as someone types an address from your organisation.

Sign-out after inactivity

Automatic sign-out after inactivity: 0 to turn it off, otherwise between 5 and 1,440 minutes. Shortcuts offered: 15 min, 30 min, 1 h, 2 h, 4 h, 8 h, or Custom.

Only mouse, keyboard, scrolling and touch count as activity. Automatic screen refreshes don't extend the session. A minute before the deadline, the user sees a warning with a Stay signed in button. The server also locks the session on its side: reopening the tab isn't enough, the user has to sign in again.

Passwords

Any password that is created or changed must be at least 12 characters, with an upper-case letter, a lower-case letter, a digit and a special character. The Minimum length in this tab can only make this baseline stricter: at 16, for example, every password in your organisation will need 16 characters or more. The rule applies when an account is created, when an administrator changes it and when users change their own password. After 5 failed attempts in 15 minutes, sign-in is suspended for the time shown.

Source: · FirstSI Docs · updated 2026-10-10