# Signing In and SSO

> Signing in to Glow with your company identity provider, and turning on two-factor authentication.

SSO lets your employees sign in to Glow with their corporate credentials, so there is no separate Glow password to manage or revoke.

## Single Sign-On (SSO)

**Setup is done with you, not from a settings screen.** Talk to your account
team or support to start, and bring two things: your identity provider's
metadata URL or XML, and the attribute names carrying email and display name.

They confirm what is involved for your particular provider before anything is
connected, so the configuration is checked against your environment rather than
assumed. Ask early rather than late — what a provider needs varies, and it is
worth settling before it sits on a launch plan.

### Managing roles

Members are invited and assigned roles under
[Team Management](/manage/workspace-settings/team-management), whether or not
SSO is connected. Automatic group-to-role mapping from your IdP is in
development, and your account team can tell you where it stands.

---

## Two-Factor Authentication (2FA)

Even if you are not using an external Identity Provider, you can add a second factor to your Glow account.

Turn it on under **[Personal Settings](/manage/workspace-settings/personal-settings)**. Glow uses standard Time-based One-Time Passwords (TOTP), so any authenticator app works: Google Authenticator, Authy, or 1Password.

### Workspace 2FA Enforcement

Each member turns 2FA on for their own account. To require a second factor
across the whole workspace today, connect SSO and let your identity provider's
policy cover everyone at once. Workspace-level enforcement inside Glow is in
development, and your account team can tell you where it stands.

## What's Next?

- Assign roles to SSO-provisioned members in [Team Management](/manage/workspace-settings/team-management).
- Review the controls and data-handling behind these features in [Security & Compliance](/manage/workspace-settings/security-compliance).
