With Require SSO for all sign-ins, you can switch password sign-in off for your whole organization in a single toggle, so SSO becomes the only way in.
Before you start
You need to be a Global Admin to see and change this setting.
The toggle works whether you sign in through Microsoft Entra ID, Google, Okta, or OneLogin.
Make sure your people can actually sign in with SSO before you turn this on - they won't have a password to fall back on.
Who can do what
| Global Admins | Building Admins | Employees |
See the Require SSO for all sign-ins toggle | Yes | No | No |
Turn SSO enforcement on or off | Yes | No | No |
Sign in with a password once enforcement is on | No | No | No |
Reset a password once enforcement is on | No | No | No |
Once enforcement is on, it applies to everyone in your organization, admins included.
The one exception is anyone whose Kadence account also belongs to another organization: a Kadence password is tied to an email address rather than to a single organization, so those people can still sign in with a password and reset it as normal.
Turn on SSO enforcement
Turning enforcement on takes one click and applies straight away across web, iOS, and Android - there's no separate setting per app.
Go to Settings and open Integrations.
Find the Single sign-on section.
Switch on Require SSO for all sign-ins. You'll see the description underneath: All users will no longer be able to sign in with a password.
Wait for the Require SSO for all sign-ins updated confirmation.
What changes for your people
As soon as enforcement is on:
Password sign-in stops working. Anyone trying to sign in with a password sees "Your organization requires signing in with SSO. Please use the SSO option below," alongside the SSO options on the login page.
Forgot password stops working. Password reset requests are turned away with the same message instead of sending a reset email.
New starters get an SSO welcome email. Newly invited and re-invited employees receive a welcome email with a Sign in button that takes them straight to the login page.
Share Signing in when your organization requires SSO with your team so they know what to expect.
Turn SSO enforcement off
Switch Require SSO for all sign-ins off in the same place. Password sign-in and password resets are available again immediately - there's no waiting period and nothing else to re-enable.
The toggle stays visible to Global Admins whenever enforcement is on, so you're never locked out of turning it back off.
SSO enforcement and passkeys
If you also use passkey sign-in, it's worth knowing how the two interact. A passkey is a separate way to sign in, verified by Kadence directly rather than through your identity provider - so anyone who has set one up can still sign in without going through SSO, even with enforcement on.
If every sign-in needs to go through your identity provider, leave passkey sign-in off.
FAQs
Do I need to set up an SSO provider before I can turn this on?
Do I need to set up an SSO provider before I can turn this on?
No. The toggle works on its own. But it's a good idea to confirm your people can sign in with SSO first, since they won't have a password to fall back on.
Why can I not see the toggle?
Why can I not see the toggle?
Only Global Admins can see and change this setting. If you are a Global Admin and it still is not there, contact Kadence support.
One of my employees can still sign in with a password. Why?
One of my employees can still sign in with a password. Why?
They almost certainly belong to more than one Kadence organization. Because the password is shared across all of them, it can't be switched off from one organization's settings.
Will this sign everyone out?
Will this sign everyone out?
No. Enforcement applies to new sign-in attempts and password resets. People who are already signed in stay signed in.
What happens to reset links I sent before turning this on?
What happens to reset links I sent before turning this on?
They stop working. Anyone holding one will see the SSO message when they try to set a new password and should sign in with SSO instead.
Our identity provider is down and nobody can sign in. What do I do?
Our identity provider is down and nobody can sign in. What do I do?
A Global Admin who can still get into Kadence can switch Require SSO for all sign-ins off in Settings > Integrations, which restores password sign-in immediately.
Need Help?
For support, reach out to:
📩 [email protected]
For more helpful articles see:
📚 Kadence Help Center

