Guides / Administration / Secure your account and set up single sign-on

Secure your account and set up single sign-on

Add passkeys and two-factor codes, connect Google or Microsoft, and route your company's email domain through an identity provider.

This guide is for anybody who wants a stronger sign-in, and for the administrator who sets up single sign-on for a company. Every task below starts in Settings > Security. Brix always keeps one working way into your account, so no action on this page can lock you out.

What you can do

Read what your account signs in with

  1. Open Settings > Security.
  2. Read the Password row under Sign-in methods.
  3. Read each row below it for a connected Google, Microsoft or single sign-on identity.
  4. Scroll to Passkeys for the devices that sign in without a password.
  5. Scroll to Two-factor authentication for the state of the second factor.
The Security page shows the Password row, the Connect Google and Connect Microsoft buttons and the top of the Passkeys section.
The Security page shows the Password row, the Connect Google and Connect Microsoft buttons and the top of the Passkeys section.
️ If the section cannot load, Brix shows an amber card with a Try again button. Your sign-in methods still work.

Send yourself a password reset link

  1. Open Settings > Security.
  2. Find the Password row under Sign-in methods.
  3. Select Reset password.
  4. Read the green banner that names your email address.
  5. Open the email from Brix.
  6. Follow the link in the email.
  7. Set a new password.
️ Brix has no change-password form. The emailed link is the only way to set a new password from inside the CMS.
️ The reset link expires after one hour. For the rest of the reset flow, see sign in and your profile.

Connect Google or Microsoft to your account

  1. Open Settings > Security.
  2. Select Connect Google or Connect Microsoft under Sign-in methods.
  3. Sign in at the provider.
  4. Wait for the browser to return to Settings > Security.
  5. Read the green banner that confirms the connection.
  6. Check the new row in the list.
️ Brix shows a Connect button only for a provider with no connection yet. A connected provider gets a row instead.
️ One Google or Microsoft account belongs to one Brix user. If somebody else already connected that account, Brix refuses the connection.

Add a passkey for this device

  1. Open Settings > Security.
  2. Scroll to Passkeys.
  3. Select Add a passkey.
  4. Type a label such as MacBook · TouchID into Label (optional).
  5. Select Create passkey.
  6. Approve the prompt from your browser or your device.
  7. Check that the new row reads Added just now · never used.
️ With one passkey already in the list, the button reads Add another passkey. Add one passkey for each device you sign in from.
️ A passkey does not replace your password. Both keep working, and you choose one at each sign-in.
️ The label is free text. The label names the device in this list, and Brix never checks the label against the device.
️ If you cancel the browser prompt, Brix asks you to try again. Select Create passkey a second time.
️ A browser with no passkey support says so. Use Chrome, Safari or Edge on a device with biometrics.

Remove a passkey

  1. Open Settings > Security.
  2. Scroll to Passkeys.
  3. Select the trash button on the passkey row you no longer want.
  4. Select Remove in the confirmation dialog.
️ The removal takes effect at once. That device can no longer sign in.

Turn on two-factor authentication

  1. Open Settings > Security.
  2. Scroll to Two-factor authentication.
  3. Select Set up.
  4. Scan the QR code with your authenticator app.
  5. Or copy the key under Or enter manually into your app.
  6. Type the 6-digit code from your app into the Step 2 field.
  7. Select Verify & turn on.
  8. Select Copy all to copy the ten recovery codes.
  9. Store the recovery codes somewhere safe.
  10. Select I've saved them.
The Two-factor authentication section shows the QR code, the manual setup key and the 6-digit code field.
The Two-factor authentication section shows the QR code, the manual setup key and the 6-digit code field.
️ Brix shows the recovery codes once, right after you turn the second factor on. Each code works one time. No page shows the codes again.
️ A recovery code replaces the 6-digit code at sign-in. Type a recovery code when you cannot reach your authenticator app.
️ Brix rejects a wrong or expired code. Wait for the next code from your app and type that one.
️ If the QR code does not draw, type the setup key into your app instead.
️ With the second factor on, the row states how many recovery codes remain.

Turn off two-factor authentication

  1. Open Settings > Security.
  2. Scroll to Two-factor authentication.
  3. Select Turn off.
  4. Type a current 6-digit code from your authenticator app.
  5. Select Turn off a second time to confirm.
️ Brix needs a current code to turn the second factor off. Without a code the section asks you for one.

Set up single sign-on for your company

A single sign-on connection routes every email address in your domains to your identity provider. Brix works with Microsoft Entra ID, Google Workspace, Okta, Auth0 and any other OIDC provider.

  1. Open Settings > Security.
  2. Scroll to Single sign-on.
  3. Select Add SSO connection.
  4. Type a name such as Acme Single Sign-On into Display name.
  5. Choose your provider in Vendor.
  6. Paste the issuer URL from your provider into Issuer URL.
  7. Select Test to check the discovery document.
  8. Paste the client ID from your provider app registration into Client ID.
  9. Paste the client secret into Client secret.
  10. Type your email domains into Email domains.
  11. Separate two or more domains with a comma.
  12. Leave Just-in-time provisioning ticked so Brix creates a member at first sign-in.
  13. Leave Enabled ticked.
  14. Select Create connection.
  15. Select Copy beside Redirect URL for your IdP.
  16. Paste that URL into the redirect-URI field of your provider.
  17. Select Done.
The New SSO connection editor shows the vendor list, the issuer test result and the redirect URL panel.
The New SSO connection editor shows the vendor list, the issuer test result and the redirect URL panel.
️ The redirect URL appears only after Brix saves the connection. Paste the URL into your provider exactly as Brix shows it, because the sign-in flow sends that same URL.
Test reads the discovery document at the issuer URL and names the authorization host it finds. A failed test names the discovery error.
️ Press Tab in an empty Email domains field to accept your own email domain.
Create connection stays disabled until Display name, Issuer URL, Client ID and Email domains all hold a value.
️ A new connection needs the client secret. Brix encrypts the secret and never shows the secret again.

Change an SSO connection

  1. Open Settings > Security.
  2. Scroll to Single sign-on.
  3. Select Edit on the connection row.
  4. Change the fields you need.
  5. Leave Client secret empty to keep the stored secret.
  6. Select Save changes.
️ Clear the Enabled checkbox to stop a connection without removing it. The row then reads Off.

Remove an SSO connection

  1. Open Settings > Security.
  2. Scroll to Single sign-on.
  3. Select the trash button on the connection row.
  4. Select Remove in the confirmation dialog.
️ Everybody in the email domains of that connection loses this way in. Give those people a password or a passkey first.

Switch your account to single sign-on only

  1. Add a passkey, or connect Google, Microsoft or your company provider.
  2. Open Settings > Security.
  3. Find the Password row.
  4. Select Use SSO only.
  5. Read the warning in the Switch to SSO-only? dialog.
  6. Select Remove password.
  7. Read the banner that confirms the account now holds no password.
Use SSO only stays hidden while the password is your only way in. The button appears once a passkey or a connected provider exists.
️ To get a password back, use Forgot password? on the sign-in page. No control on this page brings the password back.

Disconnect a linked account

  1. Open Settings > Security.
  2. Find the provider row under Sign-in methods.
  3. Select the trash button at the end of the row.
  4. Select Disconnect in the confirmation dialog.
️ The trash button stays disabled while that identity is your only way to sign in. The tooltip says so.

To give an integration its own credential instead of a person, see API keys and integrations. To set what each member can do, see organization, people and roles. To read who changed what, see proof of play and the audit log.

Ready to get started?

Open Brix Portal