What authentication methods are available in Dovetail?
By default, a user can sign up and log in to a workspace with:- Password - Use email address and create password for log in.
- Google - Use your Google account email address and password for log in for sign up and log in to Dovetail
- Microsoft - Use your Microsoft account email address and password for sign up and log in to Dovetail.
- SSO via an identity provider - Use your identity provider for sign up and log in to Dovetail.
Decide whether to enable automatic account creation
You want to encourage broad adoption of Dovetail so knowledge about your customer’s an be widely consumed, but you don’t want a manual approval bottleneck for every new user who just wants to view a project. At the same time, you can’t have an uncontrolled free-for-all. Workspace admins on Business and Enterprise plans have the option to disable automatic account creation, which allows anyone with an approved email domain to join your workspace when they create a Dovetail account. For example, if your organization has approved the email domain@acme.com, anyone that signs up to Dovetail with that domain can sign up as a viewer to that workspace.
- If you haven’t already, enter an allowed email address domain under Domains.
Please note that:
- Viewers are only available on select legacy plans and our Enterprise plan.
- Automatic account creation is enabled by default.
- Managing automatic account creation is only available on Professional (legacy), Business, and Enterprise plans
Set up SSO for your workspace
Managing separate passwords for each application is a major security risk (weak/reused passwords) and an administrative burden. Manually provisioning Dovetail accounts for new hires and, crucially, deprovisioning them for leavers, is time-consuming and prone to human error. A forgotten account is a significant security hole. There are three single sign-on options that you can enable for your workspace: your identity provider, Google workspace, and Microsoft. These all aim to solve three core admin challenges at once.Enhanced security
-
-
-
- Eliminates weak, Dovetail-specific passwords and enforces your company’s central security policies (like MFA) on Dovetail access.
-
-
Automated provisioning
-
-
- User access is managed centrally. When an employee is deactivated in your IdP, their access to Dovetail is instantly and automatically revoked, closing the offboarding security gap. 4.
-
Reduced overhead
-
-
-
- Removes password reset requests and automates the onboarding/offboarding lifecycle, freeing up valuable admin time.
-
-
With your identity provider
It is common for organizations to use an SSO identity provider (IdP) to centralize access control, consolidate apps, and streamline user management. Integrate Dovetail with your company’s Identity Provider (IdP) and enforce it as the sole method of authentication. If you are currently using SSO at your organization, learn how to activate SSO for your Dovetail workspace. Once activated, you can enforce SSO as the only log in method for all users.- To do this, open ⚙️ Settings → Authentication.
- First, ensure your organization’s email domain is added under Allowed email address domains.
- From there, navigate to Authentication methods and toggle off Password, Google and Microsoft while leaving SSO via identity provider toggled on.
With Google workspace or Microsoft
If your company uses Google Workspace or Microsoft 365 as its primary identity system, you can leverage it for a simpler, more secure login experience than passwords. Once activated, you can enforce Google or Microsoft as the only login method.- To do this, open ⚙️ Settings → Authentication.
- First, ensure your organization’s email domain is added under Allowed email address domains.
- From there, navigate to Authentication methods and disable Password while leaving Google or Microsoft enabled.