> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.superpath.io/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# How to Set a Second Authentication Type for Company Staff

# How to Set a Second Authentication Type for Company Staff

**In this article:**
* Overview
* Before you start
* How to set a second authentication type
* How domain matching works
* What happens on the next sync
* Things to keep in mind
* Troubleshooting
* FAQs
* Who can do this

## Overview
Most organisations have a mixed workforce. Office staff have a company email address and can sign in with your corporate identity provider, such as Microsoft, Google or single sign-on. Contractors, casuals and other contingent workers are in the same HRIS, but they use personal email addresses, so they cannot use corporate sign-in at all.

Until now your HRIS integration created everyone with a single sign-in method, which forced a compromise. Choosing SSO locked your contractors out. Choosing a password or magic link meant your office staff lost the SSO experience.

**Company user creation** solves this. You nominate your company email domain, then choose a second authentication type that applies only to people whose email address matches it. Everyone else keeps the method you set under **User creation**.

A typical setup looks like this: **User creation** is set to **Create with Magic Link** for your contractors, **Company user creation** is set to **Create with Microsoft** for your office staff, and **Company email domain** is set to `company.com`.

This is available on all six HRIS integrations: foundU, BambooHR, Employment Hero, Deputy, HiBob and Worknice. foundU and Worknice are available only for accounts hosted in the United States and Australia regions.

## Before you start
* Your HRIS integration needs to be connected already. This setting is part of the integration's configuration, not a separate connection.
* Know the exact email domain or domains your company staff use, for example `company.com` or `company.com.au`.
* If you plan to choose **Create with SAML**, set up Custom SSO first. See [How to Connect SAML SSO](https://help.superpath.io/en/article/how-to-connect-saml-sso-1nf8n4q/). Without it, every matching person fails to be created.
* Check **Settings → Security** allows both of the methods you are about to use. If you enforce authentication types, people can only sign in with a method you have allowed. See [How to Enforce a Login Authentication Type](https://help.superpath.io/en/article/how-to-enforce-a-login-authentication-type-189fkrj/).

## How to set a second authentication type
1. Go to **Settings → Integrations**.
2. Find your HRIS integration and click **Manage**.
3. If the integration is already connected, click **Unlock to edit** so you can change the connection details.
4. Under **User creation**, choose the method for everyone who is not company staff, for example **Create with Magic Link**.
5. Under **Company user creation**, choose the method for your company staff, for example **Create with Microsoft**. Leaving this as **Same as user creation** keeps the integration behaving exactly as it does today.
6. Scroll down to the connection details and enter your domain in **Company email domain**. Separate multiple domains with a comma, and do not include the @ symbol.
7. Click **Save** to apply the change.

> **Note:** On foundU, BambooHR and Deputy you will also see a field called **Company domain**. That is a different setting, and it holds the subdomain you use to reach your HRIS, such as the `acme` in `acme.foundu.com.au`. **Company email domain** is the one that controls this feature.

## How domain matching works
SuperPath compares the part of each person's email address after the @ symbol with the domains you entered. The match has to be exact.

| Company email domain | Person's email | Result |
|---|---|---|
| `company.com` | `jane@company.com` | Company authentication type |
| `company.com` | `Jane@COMPANY.com` | Company authentication type, because case is ignored |
| `company.com` | `bob@gmail.com` | Default authentication type |
| `company.com` | `sam@au.company.com` | Default authentication type, because subdomains do not match |
| `company.com, company.com.au` | `sam@company.com.au` | Company authentication type |

If your organisation uses more than one domain, list every one of them separated by commas. Subdomains are never matched automatically, which is deliberate: it stops an outside contractor on a lookalike address quietly landing inside your company sign-in method.

Entries must be a plain domain with at least one dot. A full email address, a bare word, a wildcard such as `*.company.com` and anything containing a space are all rejected when you save.

## What happens on the next sync
* When your HRIS creates a new person whose email matches your company email domain, SuperPath creates them with your **Company user creation** method.
* Everyone else is created with your **User creation** method, exactly as before.
* People who already exist in SuperPath are not changed. This setting only applies at the moment someone is created.
* **Send Welcome Email** works the same way for both groups, if you have it turned on.

> **Note:** A company email domain match takes priority over everything else, including **Manual** and **Invite Users**. If **User creation** is set to **Manual** to deliberately hold people back, matching company staff will still be created automatically. If it is set to **Invite Users**, matching company staff are created straight away rather than being sent an invitation.

## Things to keep in mind
* This applies to new people only. Nobody who is already in SuperPath has their sign-in method changed, now or on later syncs. To change someone who already exists, see [How to Change a Person's Login Type](https://help.superpath.io/en/article/how-to-change-a-persons-login-type-mogu4o/), or for a bulk move to SSO see [How to Migrate Users to SAML Authentication](https://help.superpath.io/en/article/how-to-migrate-users-to-saml-authentication-121x1hq/).
* Because a domain match overrides **Manual** and **Invite Users**, turning this on can create more people than your integration created before. Check the effect on your licence count if you are close to your limit.
* **Create with SAML** only works once Custom SSO is configured for your account. If it is not, matching people fail to be created and each failure appears in your integration logs.
* Your security settings still decide how people can actually sign in. If you enforce authentication types, make sure both methods are allowed, otherwise one group will be created successfully and then be unable to sign in.
* You can set two authentication types per integration, one default and one for your company domain. There is no way to add a third.
* This is not the same as [auto approving sign ups from your email domain](https://help.superpath.io/en/article/how-to-auto-approve-sign-ups-from-your-email-domain-gfyfiq/), which controls self sign up rather than how your HRIS creates people.
* On Employment Hero, if you have chosen to sync personal email addresses, the match runs against those personal addresses. Company staff will not match in that setup.

## Troubleshooting
**Everyone is still being created with the default method.** The most likely cause is that **Company email domain** is empty or the domains you entered are not valid. When that happens SuperPath falls back to your default method for everyone rather than stopping the sync. Open **Settings → Integration Logs**, filter the action to **Create People (Company)**, and look for a failed entry explaining which part is wrong. See [Integration Logs](https://help.superpath.io/en/article/integration-logs-monitor-and-troubleshoot-your-integrations-1jva0bk/).

**Only some of my company staff got the company method.** Check their email domains against what you entered. A person on a subdomain such as `au.company.com` does not match `company.com`, and a second company domain has to be listed explicitly.

**One of my domains has a typo.** Valid domains in the list keep working and the invalid ones are ignored, so the feature does not go offline. You will see a failed **Create People (Company)** entry in your integration logs telling you an entry is not a valid domain.

**My SAML people are failing to be created.** Custom SSO is not configured for your account yet. Set it up, then run a sync again.

> **Good to know:** The configuration messages in your integration logs appear as failed entries under **Create People (Company)**, and they are written at most once an hour per integration. A failed entry there is telling you the setting needs attention, not that your whole sync failed.

## FAQs
**Does this change how people who already use SuperPath sign in?**
No. The setting only applies when your HRIS creates somebody new. Everyone who already exists keeps their current sign-in method.

**Can I use this with Invite Users or Manual?**
Yes. Your company staff are created with the company method, and everyone else is invited or held back as usual. Be aware that matching people are created automatically even when **User creation** is set to **Manual**.

**Can I list more than one domain?**
Yes. Separate them with commas, for example `company.com, company.com.au`. Spaces and semicolons are not valid separators.

**Will a subdomain such as au.company.com match?**
No. Matching is exact, so list every domain you use.

**Can I use a public domain like gmail.com?**
It will be accepted, but we do not recommend it. A public domain would apply your company sign in method to anybody with that kind of address, which is rarely what you want.

**What happens if someone's email address changes later?**
Nothing changes automatically, because the setting only applies at creation. Change their login type on their profile if you need to move them.

**Which integrations support this?**
foundU, BambooHR, Employment Hero, Deputy, HiBob and Worknice.

## Who can do this
Only **Owners** and **Admins** can set this up, because they are the only roles that can open **Settings → Integrations** and change an integration's configuration. **Managers**, **People Managers**, **Content Managers**, **Instructors**, **Employees** and **Restricted** users cannot. Choosing **Create with SAML** also requires Custom SSO to be enabled for your account.