Authentication and single sign-on settings
The Authentication page sets how people sign in to your workspace: your password rules, and single sign-on (SSO) through an outside identity provider. You reach it under Security → Authentication.
Only Site Admins can open this page, and you need the Editor role to change anything on it — a Site Admin with another role can view the settings but not save them.
Password settings
The Passwords panel controls the rules every member's password must meet.
Increased Password Strength
Turn on Increased Password Strength to require stronger passwords.
- Off (default): at least 8 characters, including a lowercase letter, an uppercase letter, and a number.
- On: at least 12 characters, including a lowercase letter, an uppercase letter, a number, and a special character.
The rule applies the next time a member sets or changes their password.
Password Expiration (Days)
Set Password Expiration (Days) to the number of days a password stays valid. When a member's password reaches that age, Trak requires them to set a new one before they can continue. Set the value to 0 to turn expiration off.
The panel also shows Session Timeout and Max Login Attempts for reference. These are set by Trak and cannot be edited here.
Single sign-on (SSO)
SSO lets your members sign in with your organization's identity provider instead of a Trak password.
Is SSO available on my plan?
SSO is available if your workspace is on:
- the Enterprise package, or
- the Professional plan with either the SSO add-on or the Enterprise Governance add-on.
It is not available on Standard plans. If SSO is not part of your plan, the Authentication page shows a banner reading "Single Sign On is not enabled for this workspace," and the SSO settings are greyed out. To add it, contact your CSM.
Available providers
Trak supports three identity providers:
- Microsoft Entra ID
- Okta
How to configure a provider
You configure each provider from the Connectors section of the Authentication page. You will need OAuth credentials from your identity provider first — a Client ID and Client Secret, plus a tenant or domain value for some providers.
Trak has a step-by-step setup guide for each provider that walks you through creating those credentials. Contact your CSM or Onboarding Specialist for the guide that matches your provider.
Once you have the credentials:
- Go to Security → Authentication.
- In the Connectors section, find the provider's card and choose Configure (or Enable).
- Under Credentials, enter the values from your identity provider:
- Microsoft Entra ID — Application (Client) ID, Client Secret, and Directory (Tenant) ID.
- Okta — Client ID, Client Secret, and your Okta Domain URL.
- Google — Client ID and Client Secret.
- Copy the two values under Workspace Information — Workspace URL and Connector Redirect URL — into your identity provider's app configuration when it asks for them.
- Choose Save.
To turn a provider off later, choose Disable on its card. This removes the stored credentials, and members can no longer sign in with that provider.
SSO options
The Single Sign On panel controls how SSO behaves once a provider is connected.
- Allowed Methods of Internal Authentication — choose whether members can sign in with a Trak username and password, with SSO, or both. Setting this to Single Sign On stops members from using a password, so they must sign in through your provider.
- SSO Enforced Domains — add email domains that must sign in through SSO. Anyone with an email on one of these domains is required to use SSO.
- Allow users to register from SSO — turns just-in-time registration on or off (see below).
- SSO Email Attribute — choose which attribute your provider returns as the person's email address (Email, Principal Name, or Mail). Leave this on Email unless your provider sends the address under a different attribute.
How just-in-time registration works
Allow users to register from SSO decides whether someone can get into your workspace the first time they sign in through your provider, based on whether they already have a Trak account.
When it is on:
- Someone whose email is not in Trak yet has an account created for them, activated, and placed in the Team Member group, and is signed in.
- Someone who already has an account that has not been activated is activated and signed in.
- Someone who already has an active account is signed in.
When it is off (only people you have already added can sign in):
- Someone with no matching account is turned away with the message "Unable to find matching user."
- Someone whose account has not been activated but who was invited is activated and signed in.
- Someone whose account has not been activated and who was never invited is turned away with "User has not been activated."
- Someone with an active account is signed in.
Either way, creating or activating a member uses a seat. If no seats are available, the sign-in fails and the person is told there are no seats available — free up or add a seat, then have them try again.