Skip to main content

Require SSO for all sign-ins

Turn on Require SSO for all sign-ins to switch off password sign-in for your organization and make SSO the only way to log in to Kadence.

Written by Liza

With Require SSO for all sign-ins, you can switch password sign-in off for your whole organization in a single toggle, so SSO becomes the only way in.


Before you start

  • You need to be a Global Admin to see and change this setting.

  • The toggle works whether you sign in through Microsoft Entra ID, Google, Okta, or OneLogin.

Make sure your people can actually sign in with SSO before you turn this on - they won't have a password to fall back on.

If you haven't set up your SSO provider yet, see the Microsoft, Okta, OneLogin, or JumpCloud setup guides first.


Who can do what

Global Admins

Building Admins

Employees

See the Require SSO for all sign-ins toggle

Yes

No

No

Turn SSO enforcement on or off

Yes

No

No

Sign in with a password once enforcement is on

No

No

No

Reset a password once enforcement is on

No

No

No

Once enforcement is on, it applies to everyone in your organization, admins included.

The one exception is anyone whose Kadence account also belongs to another organization: a Kadence password is tied to an email address rather than to a single organization, so those people can still sign in with a password and reset it as normal.


Turn on SSO enforcement

Turning enforcement on takes one click and applies straight away across web, iOS, and Android - there's no separate setting per app.

  1. Go to Settings and open Integrations.

  2. Find the Single sign-on section.

  3. Switch on Require SSO for all sign-ins. You'll see the description underneath: All users will no longer be able to sign in with a password.

  4. Wait for the Require SSO for all sign-ins updated confirmation.
    ​

    Enforce SSO

What changes for your people

As soon as enforcement is on:

  • Password sign-in stops working. Anyone trying to sign in with a password sees "Your organization requires signing in with SSO. Please use the SSO option below," alongside the SSO options on the login page.
    ​

  • Forgot password stops working. Password reset requests are turned away with the same message instead of sending a reset email.
    ​

  • New starters get an SSO welcome email. Newly invited and re-invited employees receive a welcome email with a Sign in button that takes them straight to the login page.
    ​
    Share Signing in when your organization requires SSO with your team so they know what to expect.


Turn SSO enforcement off

Switch Require SSO for all sign-ins off in the same place. Password sign-in and password resets are available again immediately - there's no waiting period and nothing else to re-enable.

The toggle stays visible to Global Admins whenever enforcement is on, so you're never locked out of turning it back off.


SSO enforcement and passkeys

If you also use passkey sign-in, it's worth knowing how the two interact. A passkey is a separate way to sign in, verified by Kadence directly rather than through your identity provider - so anyone who has set one up can still sign in without going through SSO, even with enforcement on.

If every sign-in needs to go through your identity provider, leave passkey sign-in off.


FAQs

Do I need to set up an SSO provider before I can turn this on?

No. The toggle works on its own. But it's a good idea to confirm your people can sign in with SSO first, since they won't have a password to fall back on.

Why can I not see the toggle?

Only Global Admins can see and change this setting. If you are a Global Admin and it still is not there, contact Kadence support.

One of my employees can still sign in with a password. Why?

They almost certainly belong to more than one Kadence organization. Because the password is shared across all of them, it can't be switched off from one organization's settings.

Will this sign everyone out?

No. Enforcement applies to new sign-in attempts and password resets. People who are already signed in stay signed in.

What happens to reset links I sent before turning this on?

They stop working. Anyone holding one will see the SSO message when they try to set a new password and should sign in with SSO instead.

Our identity provider is down and nobody can sign in. What do I do?

A Global Admin who can still get into Kadence can switch Require SSO for all sign-ins off in Settings > Integrations, which restores password sign-in immediately.


Need Help?

For support, reach out to:
📩 [email protected]

For more helpful articles see:
📚 Kadence Help Center

Did this answer your question?