Organization Owners can choose Google Workspace and Microsoft Entra ID sign-in, then decide whether members may still use an email one-time password.
Email codes
Email one-time password (OTP) sign-in is available by default:
- Enter your email address.
- Display.dev sends a six-digit code.
- Enter the code to finish signing in.
The dashboard and dsp login use the same flow. Turning on Google or Microsoft does not disable email codes.
Configure single sign-on
Google and Microsoft single sign-on (SSO) require Pro or Enterprise. Both providers are available when SSO first becomes available; an Owner can keep both or turn either one off from Settings → General → Single sign-on:
- Turn on Google Workspace, Microsoft Entra ID, or both.
- If you enable Microsoft, optionally enter the Azure Tenant ID shown in the dashboard. Microsoft also calls this value a Directory ID.
- Select Save.
If both providers are enabled, members can choose either one. On Free or Solo, the settings page links to Settings → Billing instead of enabling the provider controls.
Restrict Microsoft to one directory
The Azure Tenant ID field is optional. When set, Display.dev checks the directory identifier returned by Microsoft during sign-in and rejects accounts from another directory.
Saving the setting stores the identifier. The check happens when a member signs in, not when you save.
Enforce SSO
Turn on Enforce single sign-on only after at least one SSO provider is enabled. Enforcement changes the sign-in paths:
- Members must use Google or Microsoft.
- Email-code sign-in stops working, including
dsp loginwith an email code. - Existing email-code sessions continue until they need to authenticate again.
The dashboard asks for confirmation before enabling enforcement.
Change or remove a provider
To remove the last enabled SSO provider, turn off Enforce single sign-on first and save. Then disable the provider and save again. Email-code sign-in remains available.
Disabling one provider does not affect another enabled provider. Members already signed in may keep their current session until they need to authenticate again.
If your organization has dropped below Pro, an Owner can still remove providers or turn off enforcement so members do not get locked out.