Workspace Login Criteria
This article explains various scenarios with SSO and email login
Path: Workspace Homepage >> Navigation Panel >> Settings >> Workspace >> Security >> Authentication >> Single Signon
| What is Workspace Login Criteria? |
|---|
| Workspace Login Criteria refers to the combination of workspace-level and community-level settings — Email login, Single Sign-On (SSO), and Community Access Rules — that determines which login method, or methods, are presented to a member at login. |
Workspace implementation gives the Workspace Administrator a choice to enable member login using SSO, Email, or both. The landing page of any workspace initially displays only the public communities available to a member; once logged in, the member gains access to both the private and public communities available to them.

Role Permissions
- Workspace Administrator: Enables and configures Single Sign-On (SSO) for the workspace from Settings >> Security >> Authentication >> Single Signon Settings, and enables the Email login option workspace-wide from Settings >> Security >> Authentication.
- Community Administrator: Sets, through Community Access Rules, which members or groups within a private, SSO-required community may log in using IdeaScale Email instead of SSO, and enables the SSO and/or Email login options available to a public community.
- Member: Logs in using whichever login method, or methods, are enabled for the workspace and, where applicable, the specific community being accessed.
Login Scenarios
Which login options are available to a member depends on how SSO and Email login are configured at the workspace level, and, in some cases, on additional Community Access Rules configured at the community level. The scenarios below describe the login experience under each configuration.
Workspace With Email Login Only
In a workspace configured with only Email login, members with access to private and public communities see only the Email login option on the login page.
The Workspace Administrator can configure the SSO login settings from Settings >> Security >> Authentication >> Single Signon.

If the Workspace Administrator wants to give members the option to log in using both Email and SSO, the Email option must be enabled under Settings >> Security >> Authentication.

Workspace With Both Email and SSO Login
Once both the SSO and Email login settings are enabled, the login page displays both options to members.

Workspace With SSO Login Only
In a workspace configured with only SSO login, members have only the SSO option available on the login page.

A Community Administrator can allow a selected group of members to log in using IdeaScale Email instead by setting the group in Community Access Rules.
Members of a private community can only log in using the workspace URL, while members of a public community can access login directly through the community landing page URL. When both SSO and Email login are enabled, members of either community type can choose either login method.
Workspace Login via SSO With Private Community
When a Community Administrator has configured a private community to require SSO, members must log in using SSO to access that community. A member may still see the option to continue with Email and be logged into the Workspace using it; however, when accessing the private community, the member is prompted to log in via SSO (see Exceptions below).

Community Login via SSO or Email With Public Community
When a Community Administrator has enabled both the SSO and Email login options in the Community Access Rules for a public community, members of that community can log in using either their SSO credential or Email login.

Exceptions
- Private Community Requiring SSO: A member with Email login enabled at the workspace level is logged into the Workspace using Email, but is still prompted to log in via SSO when accessing a private community that has been configured to require it.
Frequently Asked Questions
What login options does a member see if the workspace has only Email login enabled?
Only the Email login option, regardless of whether the member has access to private or public communities.
Can a member use Email login on a workspace configured for SSO only?
Not by default. Members see only the SSO option, unless a Community Administrator has designated a group of members through Community Access Rules to log in with IdeaScale Email instead.
Does logging into the Workspace with Email guarantee access to a private, SSO-required community?
No. A member logged into the Workspace using Email login is still prompted to log in via SSO when accessing a private community that has been configured to require it.
What login options are available on a public community that has both Email and SSO enabled?
Members of that public community can log in using either their SSO credential or an Email login.
Related Articles
- Help Article for Workspace Single Sign-On Settings
- Help Article for Workspace Authentication
- Help Article for Mixed Authentication / Multiple Provider Single Sign-On
- Help Article for Community Access Control
Last Updated: August 18, 2026