Skip to main content

SSO Enforcement Modes

Learn about the three SSO enforcement modes and how to control how your team signs in to Tomba.

Written by Tomba.io Team

SSO Enforcement Modes

Once you've set up SAML SSO, you can control how your team members sign in to Tomba. Choose the level of enforcement that's right for your organization.

To change the enforcement mode, go to Settings > Workspace > SAML SSO and scroll to Authentication Method.

[Image: enforcement_radio_group.png] — Upload this image


🔓 All Methods

Best for: Getting started with SSO or teams that need flexibility.

Members can sign in using any method — email and password, OAuth (Google, etc.), or SSO. This is the default setting and a good choice while you're testing your SSO configuration.


🔑 SSO Preferred

Best for: Encouraging SSO adoption without forcing it.

SSO is available as a sign-in option alongside other methods. Members will see the SSO option on the sign-in page if you've verified your domain.


🔒 Only SAML SSO

Best for: Maximum security and centralized access control.

All workspace members must sign in through your identity provider. Password and OAuth sign-in are disabled for regular members.

[Image: enforcement_only_sso.png] — Upload this image

Safety net: Workspace owners and admins always keep password sign-in as a fallback, so you can never get locked out if your identity provider has an issue.


👤 JIT Provisioning

Alongside enforcement modes, you can toggle JIT (Just-In-Time) provisioning:

[Image: jit_provisioning_toggle.png] — Upload this image

  • Enabled — When someone signs in via SSO for the first time and doesn't have a Tomba account, one is created automatically. They're added to your workspace with the default role.

  • Disabled — Only people who are already members of your workspace can sign in with SSO. New users who attempt SSO will be turned away.

JIT provisioning is great for large teams where managing individual invitations isn't practical.


💡 Recommendations

  1. Start with "All methods" while testing your SSO setup. Make sure everything works before restricting sign-in options.

  2. Verify your domain first. This lets members discover SSO from the sign-in page, which makes the transition smoother.

  3. Communicate the change to your team before switching to "Only SAML SSO." Let them know they'll need to use their company login going forward.

  4. Enable JIT provisioning if you want new hires to get access automatically — no manual invitations or SCIM setup required.


Related Resources

Need Help?

Got questions about SSO enforcement? Contact our support team — we're here to help!

Did this answer your question?