> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.superpath.io/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# How to Enforce a Login Authentication Type

# How to Enforce a Login Authentication Type

**In this article:**
* Overview
* How to enforce an authentication type
* Things to keep in mind
* FAQs
* Who can do this

## Overview
The **Enforce authentication type** setting lets you control how people sign in to your SuperPath account by restricting it to one or more approved methods. Enforcing a consistent sign-in method improves security and stops people signing in in ways you haven't approved. You can enforce any combination of Email / Password, Magic Link, Google Login, Microsoft Login and Custom SSO (SAML).

## How to enforce an authentication type
1. Sign in to SuperPath as an **Owner** or **Admin**, using the method you want to enforce — you can only enforce a method you are currently signed in with.
2. Go to **Settings**.
![](https://storage.crisp.chat/users/helpdesk/website/-/c/0/6/4/c0645e580ffc0800/image_16aww96.png)
3. Open the **Security** section.
![](https://storage.crisp.chat/users/helpdesk/website/-/c/0/6/4/c0645e580ffc0800/image_15f4fs0.png)
4. Find **Enforce authentication type**, under "Restrict access to your account to a single authentication type".
![](https://storage.crisp.chat/users/helpdesk/website/-/c/0/6/4/c0645e580ffc0800/image_1fap2kq.png)
5. Turn the toggle on.
6. Select the authentication type(s) you want to allow — you can choose more than one.
![](https://storage.crisp.chat/users/helpdesk/website/-/c/0/6/4/c0645e580ffc0800/image_hfpz5t.png)
7. Click **Save changes** to apply the change.
![](https://storage.crisp.chat/users/helpdesk/website/-/c/0/6/4/c0645e580ffc0800/image_1824qx8.png)

Once enforced, the sign-in page shows only the methods you allowed. For example, allowing both Email / Password and Magic Link looks like this:
![](https://storage.crisp.chat/users/helpdesk/website/-/c/0/6/4/c0645e580ffc0800/image_w2vlqj.png)
And allowing only Email / Password looks like this:
![](https://storage.crisp.chat/users/helpdesk/website/-/c/0/6/4/c0645e580ffc0800/image_1gjwck3.png)

## Things to keep in mind
* **Enforce authentication type** is only available on paid plans.
* You can only enforce a method you are currently signed in with. If you try to enforce a method you aren't using, SuperPath blocks the change and asks you to sign in with that method first.
* The setting only appears when you're signed in with a method other than email and password, so sign in with the method you want to enforce (for example Google or Magic Link) before turning it on.
* You can enforce more than one method at once — for example Google Login and Microsoft Login — by selecting each one.
* This controls *how* people sign in. It's separate from **Custom SSO (SAML)** (which connects your identity provider) and from the domain-based auto-approve setting.
* When you connect or update Custom SSO (SAML), SuperPath adds **Custom SSO (SAML)** to the methods you allow here rather than replacing them, so anything else you had selected stays selected. That matters for a mixed workforce: your office staff can use SSO while contractors keep signing in with a magic link or a password. Removing your SAML configuration takes **Custom SSO (SAML)** back off the list and leaves the other methods in place. If you want SSO to be the only way in, deselect the other methods here yourself.

## FAQs
**Which methods can I enforce?**
Email / Password, Magic Link, Google Login, Microsoft Login and Custom SSO (SAML). You can allow any combination.

**Why can't I select the method I want?**
You can only enforce a method you are currently signed in with. Sign in using that method first, then set the enforcement. If you're signed in with email and password, the setting won't appear — sign in with the method you want to enforce instead.

**Can I allow more than one way to sign in?**
Yes. Select every method you want to permit; team members must then use one of the methods you've chosen.

**I don't see the Enforce authentication type setting. Why?**
It's only available on paid plans, and only when you're signed in with a method other than email and password. It's also restricted to Owners and Admins.

## Who can do this
Only **Owners** and **Admins** can open **Settings** and change security settings — the whole `/settings` area is restricted to these two roles, so **Managers**, **People Managers**, **Content Managers**, **Instructors**, **Employees** and **Restricted** users cannot. Enforcing an authentication type also requires a paid plan and that you're signed in with the method you want to enforce.
