> ## Documentation Index
> Fetch the complete documentation index at: https://docs.y.uno/llms.txt
> Use this file to discover all available pages before exploring further.

# Security

> Configure single sign-on and the login methods your organization allows

The **Security** tab holds the sign-in settings that apply to your whole organization: **single sign-on** and **login methods**.

Open it from **Organization → Security**.

<Note>
  **You need the right permission**

  This tab is available to organization admins and to members whose role carries the SSO management permission. Security permissions can only be granted at the organization level — see [Roles](/docs/using-yuno/organization/roles).
</Note>

## Domain verification

Before you can configure SSO you have to prove you own the domain your team signs in with. The **Domain verification** panel is the first thing on this tab, and **Configure domain** starts that process.

Until a domain is verified, **Configure SSO** stays disabled — the tab says so directly: *"You must verify a domain before configuring SSO."* If you are planning an SSO rollout, start here rather than at the SSO panel.

## Single sign-on (SSO)

Let your team sign in through your own identity provider using **SAML 2.0**. This reduces the number of passwords in circulation and lets you manage access centrally.

The panel shows whether an SSO connection is configured yet, and **Configure SSO** is where you set it up once your domain is verified.

Step-by-step guides:

* [Single Sign-On (SSO) overview](/docs/using-yuno/organization/single-sign-on-sso/index)
* [Okta SSO guide](/docs/using-yuno/organization/single-sign-on-sso/okta-sso-guide)
* [Microsoft Entra ID SSO guide](/docs/using-yuno/organization/single-sign-on-sso/microsoft-entra-id-sso-guide)

SAML 2.0 is the supported protocol. OpenID Connect (OIDC), SCIM user provisioning, and automatic permission assignment from identity-provider groups are not supported.

## Login methods

**Login methods** lists the ways your team can sign in — **Email and password**, and **Single Sign-On** — and shows which are enabled for your organization.

<Note>
  **These are not self-service**

  Both rows read *"Contact the Yuno team to update this setting."* You can see which login methods are active, but changing them is a request to Yuno rather than a toggle you control.
</Note>

## Personal security settings

Your own password and two-factor authentication are not here. They stay in the **Security** page behind your profile image, because they belong to you rather than to the organization.

<Note>
  **Organization-wide 2FA enforcement**

  Enforcing two-factor authentication across your organization is a policy Yuno manages for you rather than a self-service setting. Contact the Yuno team to change your organization's 2FA enforcement policy.
</Note>

## Security best practices

* **Use SSO where you can** — it centralizes access and removes passwords from circulation.
* **Enable two-factor authentication** on your own account, so a compromised password is not enough to get in.
* **Review access regularly** — check [Team members](/docs/using-yuno/organization/team-members) for people who no longer need access, and [Audit logs](/docs/using-yuno/settings/audit-logs) for what changed.
