After you set up an SSO connection, you manage it from the same Single Sign-On view in your account settings. From there, you can add or remove domains, edit the connection, invite connection managers, or delete the connection.
Prerequisites
- You're a manager (Admin or Owner) of the SSO connection.
View your SSO connections
- Go to Account settings > Single Sign-On.
- Select a connection to open it.
The connection view lists Invite managers, Add domain, Edit, and Delete.
Manage domains
Add a domain
- Select Add domain.
- Enter the domain, then select Add. Lansweeper adds the domain and shows a code to verify ownership.
- Add the code as a TXT record with your DNS provider.
- Return to the connection view and select Verify domain.
A domain shows as Verified or Not verified in the connection view.
Enable or disable a domain
Each domain has an Enable domain toggle.
Turning it on enables SSO for that domain. Users with an email address on the domain can log in with SSO, and password login remains available unless a site requires SSO.
Turning it off disables SSO for the domain. Users with an email address on the domain lose SSO access and must log in with their Lansweeper email and password.
Remove a domain
You can only remove a domain after you disable it.
- Disable the domain, if it's still enabled.
- Select Remove domain.
- In the dialog, select Remove.
Edit a connection
Select Edit to change the connection's name, IdP details, IdP-initiated SSO setting, NameID format, or email claim. See Set up an SSO connection for details on each field.
Delete a connection
Deleting a connection permanently removes it and all its domains.
- Select Delete.
- In the dialog, select Delete.
Deleting an SSO connection permanently removes the connection and its domains. Users on those domains lose SSO access and must log in with a Lansweeper password.
Manage connection managers
An SSO connection needs at least one owner. You can invite up to 10 managers in total, including yourself.
| Role | Can do |
|---|---|
| Admin | Edit the SSO connection's settings. |
| Owner | Edit the SSO connection's settings, and manage other managers. |
Invite a manager
- Select Invite managers.
- Enter the email addresses of the people you want to invite.
- Select a role: Admin or Owner.
- Select Send invite.
Change a manager's role
- Select the manager.
- Select Change role.
- In the dialog, select the new role, then select Change.
Remove a manager
- Select the manager.
- Select Remove as manager.
Leave a connection
You can select Leave connection next to your own name to remove yourself as a manager.
If you're the only owner of a connection, Leave connection is disabled. Invite another owner first, and wait for them to accept, before you leave.
Require SSO for a site
You can require SSO for a specific site instead of leaving it optional. Go to Site settings > General > Authentication and enable Require SSO for this site.