Administration
Set Up SSO and User Provisioning
What to expect when your organization moves beyond basic sign-in and starts configuring MFA enforcement, SSO domains, and lifecycle-managed user access.
Updated August 26, 2026
When this matters
This article is for organizations that need stronger identity controls than basic email and password access.
That usually includes:
- larger teams
- stricter security requirements
- centralized IT ownership
- planned SSO or SCIM rollout
Multi-factor authentication
Rivolq supports MFA via TOTP (authenticator apps) and SMS verification codes, and admins can enforce MFA org-wide.
In practice, teams should expect:
- enrollment to happen under Settings then Security
- verification codes to be short-lived and single-use
- users to complete enrollment in one active session
If an MFA setup attempt is interrupted, start the enrollment flow again instead of reusing a stale code.
SSO domain verification
Before SSO can be enabled for a domain, the organization must prove control of that domain.
That typically means:
- 01add the domain in settings
- 02publish the verification DNS record
- 03verify the record from the admin flow
- 04enable SSO after verification succeeds
User provisioning expectations
If your team uses lifecycle-managed access, the important rule is simple:
- only provision users for the verified domain your organization controls
That keeps identity setup aligned with the organization boundary and reduces accidental account drift.
Before you turn identity features on
Make sure you know:
- who owns identity configuration
- which email domain is authoritative
- which users should remain local administrators
- how provisioning errors will be handled
Best practice
Roll out identity changes deliberately.
Start with:
- one verified domain
- a small pilot group
- a known admin owner
- a tested recovery path if someone loses access
Still need help?
Reach out for broken behavior, account-specific help, or billing questions.
