SSO Enforcement Modes
Once you've set up SAML SSO, you can control how your team members sign in to Tomba. Choose the level of enforcement that's right for your organization.
To change the enforcement mode, go to Settings > Workspace > SAML SSO and scroll to Authentication Method.
[Image: enforcement_radio_group.png] — Upload this image
🔓 All Methods
Best for: Getting started with SSO or teams that need flexibility.
Members can sign in using any method — email and password, OAuth (Google, etc.), or SSO. This is the default setting and a good choice while you're testing your SSO configuration.
🔑 SSO Preferred
Best for: Encouraging SSO adoption without forcing it.
SSO is available as a sign-in option alongside other methods. Members will see the SSO option on the sign-in page if you've verified your domain.
🔒 Only SAML SSO
Best for: Maximum security and centralized access control.
All workspace members must sign in through your identity provider. Password and OAuth sign-in are disabled for regular members.
[Image: enforcement_only_sso.png] — Upload this image
Safety net: Workspace owners and admins always keep password sign-in as a fallback, so you can never get locked out if your identity provider has an issue.
👤 JIT Provisioning
Alongside enforcement modes, you can toggle JIT (Just-In-Time) provisioning:
[Image: jit_provisioning_toggle.png] — Upload this image
Enabled — When someone signs in via SSO for the first time and doesn't have a Tomba account, one is created automatically. They're added to your workspace with the default role.
Disabled — Only people who are already members of your workspace can sign in with SSO. New users who attempt SSO will be turned away.
JIT provisioning is great for large teams where managing individual invitations isn't practical.
💡 Recommendations
Start with "All methods" while testing your SSO setup. Make sure everything works before restricting sign-in options.
Verify your domain first. This lets members discover SSO from the sign-in page, which makes the transition smoother.
Communicate the change to your team before switching to "Only SAML SSO." Let them know they'll need to use their company login going forward.
Enable JIT provisioning if you want new hires to get access automatically — no manual invitations or SCIM setup required.
Related Resources
SAML Single Sign-On (SSO) — SSO overview
Set Up SAML SSO — Step-by-step setup guide
Verify Your Domain for SSO — Enable SSO login discovery
Team Member Roles — Understand workspace roles and permissions
Need Help?
Got questions about SSO enforcement? Contact our support team — we're here to help!
