Use this article to set up and manage authentication for your Fin workspace — including enabling Google Sign-In, requiring Two-Factor Authentication (2FA), switching between login methods, and troubleshooting common login issues. Workspace admins with access to general and security settings can configure authentication methods for all teammates. Individual teammates can manage their own 2FA from their personal account settings.
You can configure the following authentication methods for your workspace:
Google Sign-In — Let teammates log in with their Google Workspace accounts
Two-Factor Authentication (2FA) — requires teammates to enter a one-time code from an authenticator app in addition to their password
SAML Single Sign-On (SSO) — Enforce authentication via your identity provider (Enterprise only)
How do I set up authentication for my workspace?
Go to Settings > Security > Workspace and choose the option you’d prefer under "Authentication methods".
The Authentication methods section shows three toggle options: Email & Password, Require Google sign in, and Require SAML.
The table below compares the four available authentication methods for Fin workspaces, including plan availability, whether workspace-wide enforcement is supported, and relative security strength.
Method | Availability | Enforcement | Security |
Email & Password | All plans | N/A | ❌ Poor |
Email & Password w / 2FA | All plans | Can be enforced | ✅ Improved |
Require Google sign in | All plans | Can be enforced | ✅ Strong |
Require SAML | Can be enforced | ✅ Strong |
Note:
You must have permission to access general and security settings to enable this.
Once you require Google SSO or SAML, make sure to disable email and password logins.
Switching between authentication methods
How do I switch from Google SSO back to email and password login?
To switch back to email and password login, go to Settings > Security > Authentication methods and toggle Google Sign-In off and Email & Password on.
The screenshot below shows the Email & Password toggle in the off state under Authentication methods.
Note: Teammates who originally signed up via Google SSO may not have a password set. They'll need to use the "Forgot your password?" link on the login page to create one before they can sign in with email and password.
How do I switch from email and password login to Google SSO?
To switch to Google SSO, go to Settings > Security > Authentication methods and toggle on Require Google sign in. Once all teammates have confirmed they can sign in with Google, disable email and password login to strengthen your workspace security. Ensure all teammates have a Google account using an email address that matches their Fin account before enforcing this method workspace-wide.
What should I do if a teammate's SSO stops working after a company email domain change?
If a teammate's company has recently changed its email domain (for example, from example@olddomain.com to example@newdomain.com), they may see this error when accepting a workspace invite:
"No active invite with your email address exists for this workspace. Invites can only be redeemed by the exact email address to which they were sent."
This happens because the teammate's Google SSO token is still linked to their old email address. To resolve this, contact the Support team — they can unlink the SSO token from the old address so the teammate can sign in with their updated email.
How do I disable email and password login?
You should disable email and password logins by toggling off Email & Password under Settings > Security > Authentication methods.
Turning off email and password login is strongly recommended. Passwords are the most common entry point for attackers. They're prone to phishing, reuse, and weak security practices. Use SSO and/or Google Sign-In with 2FA to provide stronger protection for your workspace.
How do I enable Google Sign-In for my workspace?
How do I set up Two-Factor Authentication (2FA) for my workspace?
If you have to let your users log in with email and password, you can add an extra layer of security with two-factor authentication. Teammates supply a unique code from an authenticator app like Google Authenticator or Authy on login.
Can be enforced workspace-wide
Each teammate sets up their own device
If teammates have not already set up two-factor authentication when you enable this for your workspace, they'll be prompted to do so on their next login.
How do I enable Google Sign-In for my workspace?
Let teammates log in with their Google Workspace accounts.
Easy to enable from your security settings
Optional domain restriction (e.g. only
@example.comusers)
How do I set up SAML SSO for my workspace?
SAML SSO (Security Assertion Markup Language Single Sign-On) allows your team to log in via your Identity Provider (IdP — a service that manages your team's logins, such as Okta, Azure AD, or OneLogin). This option is available on Enterprise plans only.
Supports Just-in-Time (JIT) provisioning — teammate accounts are created automatically on their first login
Supports SCIM (System for Cross-domain Identity Management) for automated account provisioning and deprovisioning
Tip: Integrating your Fin workspace with an identity provider like Okta or OneLogin is the most secure and simple way for your team to log in.
Follow the steps in this article to configure your identity provider, to require SAML SSO (Single Sign On) from all your teammates, or offer it as one of your sign in options.
How does Intercom protect against suspicious logins?
Your Fin workspace also continuously monitors login activity and automatically protects a teammate account. If we detect a suspicious email / password login for a teammate account, we will force email verification before the login can be completed. This includes:
Intelligent Login & Session Protection: Extra verification for unusual login patterns and advanced measures against abuse.
Security Notifications: Timely alerts about potential security events.
The teammate will receive a verification email like so and will have to enter the unique verification token before they can proceed.
Note: Resetting your admin password immediately forces logout across all mobile sessions, revoking access on all devices. Previously, mobile sessions remained active until the app was reinstalled or the user logged out manually.
How do teammates manage their own authentication settings?
How do I enable 2FA on my individual Fin account?
You can enable 2FA on your own Fin account, separate from the settings of any workspace you're a member of, from Settings > Account security under the Two Factor Authentication (2FA) section.
The Account security settings page shows the Two Factor Authentication (2FA) section with an Enable 2FA toggle and a link to download Recovery Codes.
A QR-based system is used to set up an authenticator app. Your Fin workspace is compatible with popular authenticator apps like Google Authenticator and Authy.
Teammates with 2FA enabled for their account should download their individual Recovery Codes by going to Settings > Account security. Once there, if 2FA is enabled, they should see a link they can click to download these codes.
Important: You should generate and securely save your recovery codes to avoid potentially being locked out of your account.
Recovery codes are especially useful if you encounter issues with your authenticator app or lose access to your device. If your recovery codes are missing or not working, you can request a new recovery code to be sent to your registered email. Use this code to log in and reset your 2FA connection by disabling and re-enabling 2FA in Settings > Account security.
Note: If you created your account with Google sign-on, you won't see an option to set up 2FA unless you set a password. You can do this by going through the password reset flow, using the 'Forgot your password?' link on the login page. Configure or disable 2FA under your account settings after regaining access.
How do I migrate my authenticator app to a new device?
To migrate to a new device, you must disable and re-enable 2FA. Follow these steps:
Go to Settings > Account security.
Toggle off Enable 2FA under "Two Factor Authentication (2FA)".
After disabling 2FA, toggle it back on to set it up with your new phone.
Scan the QR code displayed on your computer screen using the authenticator app on your new phone.
The 2FA setup screen shows the Enable 2FA toggle in the on state with a QR code to scan using your authenticator app.
Troubleshooting 2FA issues
Why are my authenticator app codes not working?
If your authenticator app codes are not working, try the following strategies:
Device Settings and App Synchronization:
Ensure your mobile device’s time and date settings are set to "Set Automatically," as discrepancies can cause codes to fail.
Restart your mobile device to re-sync the time settings of your authenticator app.
App Reconfiguration:
Reset your 2FA connection by disabling and re-enabling it in Settings > Account security. Then, scan a new QR code using your authenticator app.
If possible, use a different authenticator app as a backup.
How do I help a teammate who has lost their 2FA device?
If a teammate is locked out of their account due to 2FA issues, a teammate with Full access on the Fin workspace can generate a recovery code on their behalf.
If recovery codes fail, the administrator can reset the failed login attempts and issue a new recovery code. Encourage the teammate to reset and reconfigure their 2FA setup to prevent future issues. Follow these steps:
Ask for Teammate Assistance:
Request a teammate to navigate to Settings > Teammates.
Generate and Send Recovery Code:
Have the teammate click on the '2FA Recovery' button next to your account.
A recovery code will be sent to your registered email address.
Use the Recovery Code:
On the 2FA login page, select Enter a recovery code.
Enter the code from the email to regain access to your account.
The Settings > Teammates page shows a 2FA Recovery button next to each teammate's name in the list. The button only appears for teammates who have 2FA enabled. Clicking it sends a recovery code to the teammate's registered email address.
What should I do after recovering access to my account?
After using a recovery code to regain access to your account following a 2FA lockout, 2FA will still be enabled. To prevent future disruptions, complete the following steps:
Navigate to Settings > Account security.
If needed, toggle off 2FA to disable it temporarily.
Re-enable 2FA and set it up with an authenticator app on a new or existing device to ensure continued security. For enhanced backup options, download additional recovery codes from your account settings for future use.
Preventative measures to ensure smooth access to your account in the future:
Always store recovery codes securely after initial setup.
Pair multiple devices with your 2FA setup where possible.
Regularly update your 2FA settings to reflect changed devices or preferences.
Why am I not receiving my verification code or login email?
If you're not receiving a verification code or login email, try the following:
Delayed Verification Codes: Use the most recent code received as long as it hasn’t expired. If expired, request a new code and use it immediately.
Codes Not Working in Mobile App: Ensure you enter the latest code and correct your mobile device’s time and date settings to prevent mismatches. Restart the app and try the code again.
Check email settings: Look in your spam, junk, or promotions folders to ensure emails from Intercom are not being filtered or delayed.
Ensure Device Time is Correct: If using a mobile app, make sure your device’s date and time are set to "Set Automatically." Restart the app and try again.
Authenticator app errors: If the authentication code generated by your app is consistently rejected, reset your 2FA connection by disabling and re-enabling it in Settings > Account security, then scan a new QR code. If the problem persists, try a different authenticator app.
What should I do if my SSO stops working after an email domain change?
If you see the following error message:
"No active invite with your email address exists for this workspace. Invites can only be redeemed by the exact email address to which they were sent. If you think you're using the right email to redeem an invite, please contact your admin for help."
This is usually caused by an SSO token mismatch. An SSO token is the unique identifier that links your Fin account to your Google account. If your company has recently changed its email domain, your SSO token is still linked to your old address.
For example changing your email from example@olddomain.com to example@newdomain.com.
In your Fin workspace, your SSO token will still be attached to your old email and when you attempt to log in with Google SSO using a new invite, it's still linked to the old domain. This triggers the error "Invites can only be redeemed by the exact email address to which they were sent."
To resolve this, please reach out to the Support team who can unlink the SSO token from your old email address, allowing you to use Google SSO with your updated address.
What happens if I update the email address on my Google account?
If you are updating an existing google account with a new email, there will be no issues. Teammate accounts are matched to Google accounts by storing the Google account ID — not the email address.
If something goes wrong, you can always use email and password to gain access (if your workspace allows email/password as login method). Note, it's possible your teammates don't have passwords set as they used Google SSO to redeem invites. In that case they can log out of their Fin workspace and reset their password from the login page.
Need more help? Get support from our Community Forum
Find answers and get help from Intercom Support and Community Experts





