# Account Security Settings

Manage account-wide login security, including 2-step verification, Single Sign-On, and domain-based access controls.

Keep your account safe with 2-step verification. Set up how users log in and control access to make sure everything stays secure and easy to manage.

## **Enable 2-Step Verification**

You can enable and manage the 2-Step Verification (2FA) method to add an extra layer of security to your account.

To require 2-Step Verification:

1. From your Emailable dashboard, navigate to [Security](https://app.emailable.com/account#security).
2. In the **2-Step Verification** section, enable the **Require 2-Step Verification** option.
3. Click **Save**.

\[1a. Account section - Security - 2FA, SSO, Limit domain login - Emailable.png\]
When enabled, all users, including the account owner, are required to use 2-Step Verification when signing in.

## **Single Sign-On (SSO)**

Single Sign-On (SSO) is an authentication method that lets users log in once using a trusted provider (such as Google or Microsoft) and access multiple applications without re-entering passwords.

### **Enable Single Sign-On (SSO)**

You can require users to sign in through a supported Single Sign-On provider.

To require Single Sign-On:

1. In the **Single Sign-On (SSO)** section, click the **Require Single Sign-On** dropdown and select the provider.
2. Select the provider you want users to sign in with.
3. Click **Save**.

\[2a. Account section - Security - 2FA, SSO, Limit domain login with SSO options - Emailable.png\]
Supported SSO providers include:

\[2a1. SSO Options - Emailable.png\]
Choosing **Any** allows users to sign in with any supported provider. Choosing **Disabled** also allows password-based logins.

### **Disable Single Sign-On (SSO)**

If you are signed in using a third-party provider, you can manage your Single Sign-On settings from the Profile section.

To disable Single Sign-On:

1. In the **Single Sign-On** section, locate your connected provider (for example, Google).
2. Click **Disable**.

\[2b. Profile section - SSO disable - Disable SSO - Emailable.png\]
After disabling SSO, you may be required to use standard login credentials (email and password) to sign in.

## **Limit Login to Specific Domains**

You can restrict SSO access so that only users with email addresses from specific domains can sign in.

To limit login to specific domains:

1. In the **Single Sign-On (SSO)** section, configure **Require Single Sign-On** as needed.
2. In the **Limit Login to Specific Domains** field, enter the domain you want to allow.
3. Click **Save**.

\[2c. Profile section - SSO Limit domain login - Emailable.png\]
Only users with email addresses from the domains you enter can sign in using your organization’s SSO provider.
