Skip to content
English
  • There are no suggestions because the search field is empty.

Which login method should I choose for my company's Tilt account?

SSO or 2FA? The right choice comes down to one question: does leave revoke identity provider access?

Which login method should I choose for my company's Tilt account?

Tilt offers three enforced login methods — SAML Single Sign On, Google Sign-In (Google Workspace), and Two Factor Authentication (2FA). The deciding factor is whether your company revokes access to your identity provider while employees are on leave. If yes, choose 2FA. If you can keep employees' identity-provider access during leave, SSO is fine.

Who this applies to / Prerequisites

  • You are an HR admin choosing between SAML SSO, Google SSO, and 2FA.
  • You need to decide before enforcing any login method.

Steps

  1. Understand your three options.
    • SAML Single Sign On (SSO): connect a SAML-compliant identity provider (IdP) so users log into Tilt through your IdP.
    • Google SSO: if your company uses Google Workspace, users log into Tilt through Google Sign-In.
    • Two-Factor Authentication (2FA): users log in with email and password, then confirm with an Authenticator App or SMS code.
  2. Ask your IT team: "Do we revoke Okta, Azure, or Google Workspace access when an employee goes on leave?"
    • Yes, we revoke access during leave → enforce 2FA. If you enforce SSO instead, employees will lose access to Tilt during leave — exactly when they need it.
    • No, we can keep access during leave (or configure the IdP to allow Tilt access only) → SSO is fine. Choose SAML SSO or Google SSO based on which identity provider you already use.
  3. If you go with email and password login instead of SSO, Tilt recommends enforcing 2FA for added security.
  4. If you're unsure about your leave-access policy, confirm with IT before enforcing anything.

What if it doesn't work

  • If you're still unsure after talking with IT about the best method, reach out to your Customer Success Manager to talk through your setup.

Limits and exceptions

  • You can only enforce ONE method at a time. Exception: if you don't enforce Google SSO, employees can still choose to use Continue with Google as an optional login method alongside email and password.
  • Enforcing SAML SSO when your company revokes IdP access during leave WILL lock employees out of Tilt during leave. Tilt cannot override this — restoring access requires IT or HR to restore identity-provider access.
  • Google SSO has the same risk if you revoke Google Workspace access during leave.
  • If you enforce Google SSO, do NOT also enforce 2FA in Tilt. See Can I enforce both Google SSO and 2FA at the same time on Tilt?
  • This decision is reversible. You can switch methods later if your needs change. See How do I switch from one enforced login method to another in Tilt?

Related questions

  • How do I enforce SAML SSO for my company's Tilt account?
  • How do I enforce Google SSO for my company's Tilt account?
  • How do I enforce 2FA for my company's Tilt account?
  • How do I switch from one enforced login method to another in Tilt?
  • Can I enforce both Google SSO and 2FA at the same time on Tilt?