Set Up Login Settings
By default, everyone signs in to RTOSafe with their email and password. On the Login Settings page you can add two extra layers:
- Multi-factor authentication (MFA) — an extra security step for admins who sign in with a password
- Single sign-on (SSO) — let staff sign in with the company Google or Microsoft account they already use, so there’s no separate RTOSafe password
Multi-Factor Authentication
MFA adds a one-time code (from an app like Google Authenticator on their phone) on top of an admin’s password. We recommend turning it on.
We recommend enabling MFA. It significantly reduces the risk of unauthorised access, even if a password is compromised.
Tick Require MFA for admins signing in with email and password and select Save Changes. Each admin will be prompted to set up MFA the next time they sign in (see Set Up MFA on Your Account). Changing this setting signs other admins out, so they’ll sign in again under the new rule.
MFA only applies to email-and-password sign-ins. It doesn’t affect admins who use Google or Microsoft SSO — their provider handles that security. Staff-only users aren’t affected either.
Sign In With a Company Account (SSO)
Single sign-on (SSO) lets your team sign in with the same work account they already use for email — their Google or Microsoft account. There’s no separate RTOSafe password to create, remember, or reset.
You turn it on for your organisation’s email domain — that’s the part of a work email address after the @. For example, everyone at firstname@yourrto.edu.au shares the domain yourrto.edu.au. Once SSO is on for that domain, everyone with an email address there signs in the same way.
Once a domain is approved, everyone whose email uses it must sign in with that provider — the password option disappears for them. Make sure all your staff on that domain have a matching Google or Microsoft account first, or they won’t be able to log in.
Go to Login Settings and find the SSO Domains section
Enter your domain (e.g. yourrto.edu.au) and choose Google or Microsoft
Select Add domain. RTOSafe reviews new domains before they take effect, so it starts as Pending approval
What Happens Next
- Pending approval — nothing changes yet; staff keep signing in the way they do now
- Approved — staff on that domain are asked to sign in with Google or Microsoft next time, and the password option no longer works for them
- You can remove a domain at any time with the ✕ — those staff go back to email and password
Common Issues
A staff member can't log in after a domain is approved
They don’t have a Google or Microsoft account for that domain. Sort out their account with the provider, or remove the domain to switch them back to a password.
"This account requires Google/Microsoft Sign-In" error
Their domain is set up for SSO, so they need to use the Google or Microsoft button instead of a password.
My domain still says "Pending approval"
RTOSafe hasn’t reviewed it yet. It won’t affect anyone’s login until it shows Approved.