Domain-Based Single Sign-On (SSO) Overview – Proof Help Center
Domain-Based Single Sign-On (SSO) for Proof allows organizations to enable secure, centralized authentication through their existing identity providers (like Okta, Microsoft Azure, or Google IDP), requiring users to log in via the organization's domain-verified IDP, disabling separate Proof passwords and usernames, and ensuring all users with the organization's email domain are provisioned and authenticated through the IDP, while owners and admins retain password access and users outside the controlled domain are recommended to use MFA.
Single Sign-On (SSO) lets your users log in to Proof using your organization's existing credentials. Instead of managing separate Proof passwords, your identity provider (IDP) — like Okta, Microsoft Azure, or Google IdP — handles authentication. Once enabled, SSO applies to all users in your organization.
Benefits of SSO
- The most secure authentication method available for your users.
- Full control over user provisioning from your identity provider.
- Seamless onboarding and integration into your existing processes.
- Authentication requirements apply across all users with your domain.
Definitions
- Service provider (SP): Proof
- Identity provider (IDP): The entity you work with to create, maintain, and manage your identity information.
Requirements to Set Up SSO
You'll need all three of the following before getting started:
- 1.Your company must be a Proof Command Center customer.
- 2.You must have authority over a domain to verify with Proof.
- 3.You must have an identity provider (IDP), such as Okta, Microsoft Azure, or Google IDP. If you're unsure whether your organization has one, check with your IT or engineering contact.
What to Expect After SSO Is Enabled
Once SSO is turned on, all users in your organization must sign in to Proof through your IDP. Here's what changes:
- Former Proof passwords will no longer work. Exception: Owners and admins with Command Center access can still use a password to log in.
- Former Proof usernames will no longer work if they don't match existing usernames in your IDP.
- Anyone with your email domain will not be able to create a new, separate Proof account.
- Users with your email domain who already have a separate Proof account will lose access if they aren't provisioned in your IDP.
If any users in your organization have email domains you don't control, you can't enforce SSO for them. It is recommended to enable MFA for those users instead.
SSO applies to signers and recipients too. If your domain has SSO enabled, anyone with that domain — including signers or recipients of a transaction — must be provisioned in your IDP to access Proof. Users who are not provisioned on the IDP will be blocked from accessing the platform entirely.
If a signer or recipient is provisioned in the IDP but new to Proof, they will be just-in-time provisioned onto Proof when the transaction is sent and can SSO in immediately.
Exception: Carbon copy (CC) recipients are not prompted for SSO. CC recipients access the transaction through a PIN or access code sent to their email via the Verify Portal — there is no user login on the Verify Portal, so SSO is not triggered. This applies even if the CC recipient's email domain has SSO enabled.
Set Up SSO
Complete these steps in order:
- 1.Verify your domain to confirm you have authority over it in Proof.
- 2.Set up single sign-on in your Proof account.
- 3.Set up SAML configurations with your identity provider.
Summary Checklist
- Confirm your organization is a Command Center customer.
- Verify your domain with Proof.
- Set up SSO in your Proof account.
- Configure SAML settings with your identity provider.
- Ensure all signers and recipients with your domain are provisioned in your IDP before SSO is enabled.
Still Unsure?
Contact your Customer Success Manager (CSM) or submit a support request for help.
Related
Multi-Signal Fraud Detection Benchmarks
Proof has developed a layered fraud detection model that combines passive signals, active checks, and collective telemetry from its Identity Authorization Network to outperform traditional passive-only methods by 600-1,300% in detecting sophisticated fraud without increasing user friction, addressing the shortcomings of standard approaches like MFA and KBA that are increasingly ineffective against targeted attacks.
Platform Tiers
The Platform Tiers offer three editions tailored to business sizes: the Standard Platform Edition for small businesses includes core features like Proof platform access, custom branding, API, select integrations, and digital certificates; the Premier Platform Edition for mid-size businesses adds Command Center Lite with SSO, additional non-production accounts, extended video storage, contractual SLA, and customizable data retention; and the Enterprise Platform Edition for large corporations further includes full Command Center access, web accessibility commitments, up to ten non-production accounts, and enterprise-grade digital encryption.
New Tools for Better Oversight, Faster Closings, and Safer APIs
The update introduces three new Command Center features for Enterprise customers to enhance management efficiency and brand consistency, a Verify Agents function for supervised, secure identity verification in high-risk transactions, and OAuth 2.0 authentication for REST APIs to improve security with manageable, short-lived tokens alongside existing API keys.
The Evolving Landscape of Authentication | Proof
The blog explores five advanced authentication methods, focusing on app-based and continuous authentication, explaining how app-based authentication uses time-sensitive codes generated on a device to prevent phishing and SIM-swapping, while continuous authentication monitors user behavior throughout a session to ensure ongoing identity verification, with Proof enhancing security by integrating these methods into a comprehensive identity assurance framework combining device, document, and biometric verification.
Business Academy Training for Proof Platform Users
The Business Academy Training for Proof Platform Users offers comprehensive resources and interactive demos covering the notarization workflow, business account setup—including user management, payment settings, co-branding, multi-factor authentication, and single sign-on—and instructions on sending notarization requests to help users effectively utilize the Notarize platform.
Multi-Factor Authentication (MFA) Overview
Proof employs multi-factor authentication (MFA) to enhance security by requiring users to provide two or more verification factors—knowledge, possession, or inherence—where login MFA, mandatory for all notary accounts, protects account access via codes sent by text or authenticator apps, while transaction MFA, available only to organizations, verifies recipient identity through phone authentication with premium tiers allowing voice call options for sign-only transactions.