New

Enterprise sign-in: SAML SSO, 2FA, and session control

SAML single sign-on with just-in-time provisioning and enforcement, two-factor authentication, and full session visibility with new-device alerts.

For teams with an identity provider, Asks now speaks SAML: SP-initiated single sign-on, just-in-time provisioning gated to your domain, an enforcement mode that makes SSO the only door in, and a break-glass owner path so a misconfigured IdP can't lock you out. Certificate-expiry alerts and an SSO audit log round it out.

For everyone: two-factor authentication on your account, a sessions page that shows every active device with one-click revocation, and email alerts on new-device logins and repeated failed attempts.

SSO in four steps

Asks implements SP-initiated SAML 2.0 and works with any compliant identity provider — Okta, Microsoft Entra, Google Workspace, and others. Configuration lives under Settings → Workspace → Security:

  1. 1
    Create the app in your IdP
    The settings page shows the service-provider values — ACS URL and entity ID — to paste into your identity provider.
  2. 2
    Enter the IdP details in Asks
    Provide the IdP entity ID, the SSO URL, and the signing certificate. Map email and name attributes if your IdP uses non-standard names, and choose the default role new users get.
  3. 3
    Verify your email domain
    Prove ownership with a DNS TXT record. Just-in-time provisioning is gated by verified domains: IdP users on a verified domain get a workspace seat automatically, with the default role you chose.
  4. 4
    Optionally enforce SSO
    With Enforce SSO on, members must sign in through the IdP — password sign-in is rejected for the workspace.
Workspace security settings with the SAML SSO configuration card showing the Service Provider values with copy buttons and the IdP configuration fields
Settings → Workspace → Security: SP values on top, IdP details below.
Availability
SAML SSO is available on Premium. Settings can be changed by owners and admins; only the owner can delete the SSO connection.

Locked out is not an option

Two safety valves apply when SSO is enforced: owners and admins with 2FA enabled keep a break-glass password sign-in, and the sole owner is never locked out. Every break-glass sign-in and every SSO configuration change is recorded in an audit log and alerts the workspace owner and admins.

Your account: 2FA and sessions

Two-factor authentication uses TOTP with any authenticator app — scan the QR code, confirm a code, and download the one-time recovery codes it generates (you can regenerate the set later with your password). Disabling 2FA requires your password and signs out your other sessions. The Sessionspage lists every device signed in to your account: revoke any you don't recognize, or revoke everything except the device you're on.

Account security settings with the change-password form, the two-factor authentication card, and the recovery codes section
Settings → Account → Security: password, 2FA, recovery codes.
Try it yourself

See what's new in your workspace

Everything on this page is live today. Asks trains on your website and resolves customer conversations on every channel — free to try, live in minutes.