<!-- RTOSafe Help — rendered version: https://rtosafe.com.au/help/login-settings -->

# Set Up Login Settings

By default, everyone signs in to RTOSafe with their email and password. On the [**Login Settings**](https://app.rtosafe.com.au/LoginSettings) page you can add two extra layers:

* **Multi-factor authentication (MFA)** — an extra security step for admins who sign in with a password
* **Single sign-on (SSO)** — let staff sign in with the company Google or Microsoft account they already use, so there's no separate RTOSafe password

***

## Multi-Factor Authentication

MFA adds a one-time code (from an app like Google Authenticator on their phone) on top of an admin's password. We recommend turning it on.

<div class="help-hint bg-green-50 border-green-300 text-green-800">
<svg class="w-5 h-5 shrink-0" fill="currentColor" viewBox="0 0 20 20"><path fill-rule="evenodd" d="M10 18a8 8 0 100-16 8 8 0 000 16zm3.707-9.293a1 1 0 00-1.414-1.414L9 10.586 7.707 9.293a1 1 0 00-1.414 1.414l2 2a1 1 0 001.414 0l4-4z" clip-rule="evenodd"></path></svg>
<div class="help-hint-content">

**We recommend enabling MFA.** It significantly reduces the risk of unauthorised access, even if a password is compromised.

</div>
</div>

Tick **Require MFA for admins signing in with email and password** and select **Save Changes**. Each admin will be prompted to set up MFA the next time they sign in (see [Set Up MFA on Your Account](/help/mfa-setup)). Changing this setting signs other admins out, so they'll sign in again under the new rule.

MFA only applies to email-and-password sign-ins. It doesn't affect admins who use Google or Microsoft SSO — their provider handles that security. Staff-only users aren't affected either.

***

## Sign In With a Company Account (SSO)

Single sign-on (SSO) lets your team sign in with the same work account they already use for email — their Google or Microsoft account. There's no separate RTOSafe password to create, remember, or reset.

You turn it on for your organisation's **email domain** — that's the part of a work email address after the @. For example, everyone at `firstname@yourrto.edu.au` shares the domain `yourrto.edu.au`. Once SSO is on for that domain, everyone with an email address there signs in the same way.

<div class="help-hint bg-yellow-50 border-yellow-300 text-yellow-800">
<svg class="w-5 h-5 shrink-0" fill="currentColor" viewBox="0 0 20 20"><path fill-rule="evenodd" d="M8.257 3.099c.765-1.36 2.722-1.36 3.486 0l5.58 9.92c.75 1.334-.213 2.98-1.742 2.98H4.42c-1.53 0-2.493-1.646-1.743-2.98l5.58-9.92zM11 13a1 1 0 11-2 0 1 1 0 012 0zm-1-8a1 1 0 00-1 1v3a1 1 0 002 0V6a1 1 0 00-1-1z" clip-rule="evenodd"></path></svg>
<div class="help-hint-content">

Once a domain is approved, **everyone** whose email uses it must sign in with that provider — the password option disappears for them. Make sure all your staff on that domain have a matching Google or Microsoft account first, or they won't be able to log in.

</div>
</div>

<div class="help-stepper">

<div class="help-step">
<div class="help-step-number">1</div>
<div class="help-step-content">

Go to [**Login Settings**](https://app.rtosafe.com.au/LoginSettings) and find the **SSO Domains** section

</div>
</div>

<div class="help-step">
<div class="help-step-number">2</div>
<div class="help-step-content">

Enter your domain (e.g. `yourrto.edu.au`) and choose **Google** or **Microsoft**

</div>
</div>

<div class="help-step">
<div class="help-step-number">3</div>
<div class="help-step-content">

Select **Add domain**. RTOSafe reviews new domains before they take effect, so it starts as **Pending approval**

</div>
</div>

</div>

***

## What Happens Next

* **Pending approval** — nothing changes yet; staff keep signing in the way they do now
* **Approved** — staff on that domain are asked to sign in with Google or Microsoft next time, and the password option no longer works for them
* You can remove a domain at any time with the **✕** — those staff go back to email and password

***

## Common Issues

<details>

<summary><strong>A staff member can't log in after a domain is approved</strong></summary>

They don't have a Google or Microsoft account for that domain. Sort out their account with the provider, or remove the domain to switch them back to a password.

</details>

<details>

<summary><strong>"This account requires Google/Microsoft Sign-In" error</strong></summary>

Their domain is set up for SSO, so they need to use the Google or Microsoft button instead of a password.

</details>

<details>

<summary><strong>My domain still says "Pending approval"</strong></summary>

RTOSafe hasn't reviewed it yet. It won't affect anyone's login until it shows **Approved**.

</details>