How do I switch from one enforced login method to another in Tilt?
Moving between SSO and 2FA? Here's the step-by-step transition for each direction, without locking anyone out.
Quick answer
You can switch enforced login methods through your company org settings in Tilt under the Security tab. Communicate the change to employees ahead of time so they know how to log in going forward.
Who this applies to / Prerequisites
- You are an HR admin at a Tilt customer.
- You have an enforced login method (SAML SSO, Google SSO, or 2FA) and want to switch to a different one.
Steps
To disable SSO and enforce 2FA:
- Communicate the change to your employees ahead of time. Share your unique Tilt URL and let them know they'll need to set a Tilt password.
- Confirm every user's work email in Tilt is their actual work email (this is used as the login credential).
- Ask employees to click Forgot Password? on your Tilt login page to generate a password for their account. Tilt uses the work email on file to locate the account and send the reset link.
- In Tilt, go to Org Settings → Security and toggle OFF the enforced SSO method.
- Toggle ON Two Factor Authentication.
- In your Identity Provider, remove Tilt as a service provider.
To disable 2FA and enforce SSO:
- Verify every user's work email in Tilt matches the email in your identity provider (Okta, Google, Azure, etc.). Matching emails means no duplicate accounts will be created.
- In Tilt, go to Org Settings → Security and toggle OFF Two Factor Authentication.
- Toggle ON your preferred SSO method.
- Complete the configuration setup for your preferred SSO method
- Communicate the change to your employees.
What if it doesn't work
- If employees can't log in after the switch, verify their work email in Tilt matches the email in your identity provider (for SSO) or that they've reset their Tilt password (for 2FA).
- Work with your Implementation Guide or Customer Success Manager if the transition doesn't go as expected.
Limits and exceptions
- Both toggles cannot be on at the same time (exception: 2FA can be optional alongside SSO if SSO is NOT enforced).
- If your users have personal email addresses (not work emails) in Tilt, SSO enforcement will fail because Tilt uses the login email to match identity provider records.
- Do NOT enforce both Google SSO and 2FA simultaneously. See Can I enforce both Google SSO and 2FA at the same time on Tilt?
Related questions
- How do I enforce SAML SSO for my company's Tilt account?
- How do I enforce Google SSO for my company's Tilt account?
- How do I enforce 2FA for my company's Tilt account?