Account and access
Configure company sign-in
Configure an identity provider, require company sign-in safely, connect directory groups to roles, and set email-domain rules.
Updated August 9, 2026
Overview
Company sign-in lets an organization require its own Microsoft 365, Okta, or other configured identity provider. Email-domain rules are separate: they limit invitation and notification addresses but do not prove how a person signed in.
Test company sign-in with an active administrator before making it required.
Access needed
| Activity | Access needed |
|---|---|
| Configure or require an identity provider | Manage sign-in security |
| Connect directory groups to access roles | Manage user access |
| Manage allowed email domains | Manage organization settings |
These protected actions require a recent MFA check.
Configure an identity provider
- Open Settings > Security & sign-in > Identity providers.
- Add or open the company provider.
- Enter the provider settings supplied by your identity administrator.
- Save and activate it.
- Test sign-in with an active FTE Tree administrator.
- Review the test account’s access.
- Only then make the provider required.
Only one company sign-in method can be required at a time. Changes take effect when a person next opens a page or takes an action.
Having the same email domain is not enough. The person must use the configured company identity.
Activate or deactivate a provider
Company sign-in services are kept in history rather than deleted. Deactivate stops required sign-in through that service and ends access provided through its groups while preserving the saved setup and activity history.
To reuse it, activate the provider, review its settings and group access, test it, and then require it if appropriate.
Do not deactivate the only working path during an outage without understanding how administrators will continue to enter the organization.
Connect company groups to roles
External groups can grant FTE Tree access roles:
- Choose the company group.
- Choose the FTE Tree role.
- For a role limited by department, choose All departments or specific departments.
- Review the permissions and departments.
- Activate the connection.
A blank department selection grants no department access. Administrators cannot grant permissions or departments beyond their own authority.
Group connections are kept in history and use Activate and Deactivate. Review them whenever company group membership, department structure, or FTE Tree roles change.
Configure allowed email domains
Open Settings > Organization > Email policy to limit invitation addresses and organization email recipients to exact domains.
For example, allowing company.com permits user@company.com but not user@mail.company.com. Add each permitted domain separately. Leaving the list blank permits any domain.
The rule applies to:
- Invitation addresses.
- The verified account email used for organization notifications.
It does not select a sign-in method, confirm company identity, or remove an existing membership. Use required company sign-in for that purpose.
Review changes
People with Manage sign-in security can review provider and enforcement history. People with Manage user access can review external group mappings and synchronized access. People with Manage organization settings can review email-policy history.
One responsibility does not reveal another responsibility’s protected history unless the person has both kinds of access.
Safe rollout checklist
- Keep at least one active administrator able to sign in.
- Test provider sign-in before enforcement.
- Map a small pilot group first.
- Confirm the role and department access.
- Require the provider.
- Verify normal and administrator sign-in.
- Run an access review after the latest group information appears in FTE Tree.
- Document the recovery contact within your organization.
Common questions
Does an allowed email domain require SSO?
No. Email policy and sign-in enforcement are separate.
Why did a group member get no department data?
The connected role may require department access, and a blank department selection grants none.
Can I delete an old provider?
Providers are kept in history. Deactivate one that should no longer be used.