Sign-in & Security

Choose a sign-in method, protect your account with two-step verification, and understand the restrictions an administrator can set for your workspace. Basic sign-in and TOTP are available on every plan; domain and tenant restrictions require Business.

Ways to sign in

FyneDesk supports three sign-in methods on the login, sign-up, and invite-acceptance screens:

  • Continue with Google — one click with your Google account. No password to create or remember.
  • Continue with Microsoft — one click with your Microsoft account (work, school, or personal).
  • Email and password — passwords must be at least 12 characters. Sign-in attempts are rate-limited, and deactivated accounts are blocked automatically.

These sign-in methods are available on every plan, including Free. Use the email and identity provider associated with your account. If a sign-in takes you to the wrong workspace or does not recognize an invitation, stop and ask your administrator for help instead of creating another account.

Restricting sign-in to your company domain

On the Business plan, an administrator can open Admin Settings → Workspace Settings → Sign-in & Security to restrict Google sign-in to approved domains or pin Microsoft sign-in to an Entra tenant. The settings and server-side checks enforce these restrictions. Signing in with Google or Microsoft does not itself require Business.

Customer-portal allowed email domains are a separate Business setting. They govern portal registration and ticket submission, not staff SSO.

Two-factor authentication (2FA)

FyneDesk supports two-step verification using time-based one-time passwords (TOTP) with an authenticator app, such as Google Authenticator, Microsoft Authenticator, 1Password, or Authy. It is available on every plan for workspace accounts.

Enabling 2FA

  1. Open My Settings from the app navigation.
  2. Switch to the Security tab.
  3. Start Two-step verification and choose an authenticator app.
  4. Scan the QR code, enter the current 6-digit code to confirm, and save the backup codes shown after enrollment. Store them somewhere secure; they are shown only once.

From then on, signing in with your email and password asks for a current 6-digit code from your authenticator app as a second step.

Signing in with Google or Microsoft?Two-factor authentication in FyneDesk applies to email-and-password sign-ins. When you sign in with Google or Microsoft, your identity provider's own security — including any 2FA you have set up there — protects the sign-in.
Lost your authenticator device?Use a saved backup code if you have one. If you have no working authenticator or backup code, contact support@fynedesk.io from your account email address for recovery assistance.

What about SAML single sign-on?

The current self-service sign-in options are email and password, Google, and Microsoft. Business administrators can restrict Google sign-in by domain and Microsoft sign-in by Entra tenant, but there is no SAML 2.0 setup flow in the app today. If you need a separate SAML connection, contact us to discuss availability rather than assuming it can be enabled from settings.

Frequently asked questions

Is two-factor authentication a paid feature?

No. TOTP two-factor authentication is free on every plan, including Free.

Which authenticator apps can I use?

Any app that supports TOTP: Google Authenticator, Microsoft Authenticator, 1Password, Authy, and most password managers.

Does 2FA apply to my customers in the portal?

The Security settings described here cover workspace accounts. Customer portal accounts (contact logins) use a separate sign-in flow.

Can I switch between password and Google/Microsoft sign-in?

Use the method associated with your account and the same email address. If switching methods does not open the expected workspace, ask your administrator to check the account rather than registering again.

I lost my phone — how do I sign in?

Try one of the backup codes you saved during enrollment. If none is available, contact support@fynedesk.io from your account email address for identity-verified recovery.