Skip to main content

Configure sign-in methods

Sign-in methods are account-wide settings. Only users with an Account admin user role or a custom user role containing Manage accounts permission can configure sign-in methods.

Before changing a sign-in method:

  1. Confirm that the method meets your agency’s authentication policy.

  2. Confirm that affected users can use the method.

  3. Communicate the change to affected users.

  4. Verify successful sign-in after the change.

  5. Review the platform audit logs for unexpected authentication activity.

Incorrect sign-in configuration can prevent authorized users from accessing the account. Follow your agency’s account-recovery procedures when planning an account-wide change.

Two-factor authentication

Two-factor authentication remains enforced regardless of the sign-in method. It cannot disable the requirement.

Two-factor authentication and single sign-on (SSO)

When two-factor authentication is enabled:

  • SSO using SAML

    DigiCert prompts you to enter an OTP when signing in, even if you have already provided an OTP to your identity provider (IdP).

  • SSO using OIDC

    DigiCert skips the OTP prompt if you have already provided an OTP to your IdP.