# Security

> Your profile, password, and 2FA, plus the organization-wide password policy and single sign-on through Google or a SAML provider.

**Security settings** cover your sign-in credentials and your organization's password and single sign-on policy. They sit in one dialog reached from the **User Profile** menu, served from `id.testsigma.com` rather than the Arcus by Testsigma app, and they split into 2 groups. **User settings** cover your own account and are available to every user. **Organization Settings** apply to everyone in the account and need administrator access.

| Setting | Group | Who changes it |
| :--- | :--- | :--- |
| Profile | User settings | You, for your own account |
| Change Password | User settings | You, for your own account |
| 2FA | User settings | You, for your own account |
| Password Policy | Organization Settings | An administrator, for everyone |
| Security (SSO) | Organization Settings | An administrator, for everyone |

## Your profile

1. Click the **User Profile** menu, then select **Profile**.

2. Edit your **First Name** and **Last Name**. Both are required.

3. Click **Update**.

Your email address appears alongside them and isn't editable here, since it identifies the account. To change your profile picture, click the pencil icon on the avatar.

## Change your password

1. Click the **User Profile** menu, then select **Change Password**.

2. Enter your **Current Password**.

3. Enter the new one in **New Password**.

4. Enter it again in **Confirm Password**.

5. Click **Update**.

A new password can't match any of your last 8 passwords. The panel states "Your new password should not be same as your last 8 passwords."

## Two-factor authentication

Two-factor authentication asks for a one-time code from an authenticator app alongside your password. You enable it for your own account, and you need an authenticator app installed before you start.

1. Click the **User Profile** menu, then select **2FA** under **User settings**.

2. Turn on the **Two-Factor Authentication** toggle. The **Confirm Your Password** dialog opens.

3. Enter your password and click **Continue**.

4. In the **Set Up Authenticator App** dialog, scan the QR code or enter the setup key in your app, then click **Continue**.

5. Enter the 6-digit code from your authenticator app in **Verify Authenticator App**, then click **Continue**.

Phone numbers used for authentication are managed under **Settings > Phone Numbers (TFA)**.

## Password policy

The password policy sets 3 account-wide controls. Each is enabled separately, so you can use one without the others.

- **Idle Session Timeout (minutes)**: signs an inactive user out after this many minutes.
- **Max Failed Login Attempts**: locks the account after this many consecutive failed sign-ins.
- **Password Change Frequency (days)**: requires a new password after this many days.

To set them:

1. Click the **User Profile** menu, then select **Password Policy** under **Organization Settings**.

2. Click **Configure**.

3. In the **Configure Password Policy** dialog, select each setting you want to enable.

4. Enter the value for each one you selected.

5. Click **Update**.

## Single sign-on

Single sign-on points authentication at your identity provider, so users sign in with existing corporate credentials and Testsigma accepts a secure token instead of a password.

Five providers are supported: **Google**, and the SAML-based **Okta**, **Azure**, **OneLogin**, and **Google Workspace**.

Only one SSO configuration can be active at a time, so enabling a second replaces the first. Verify a new configuration with one account before applying it to the organization.

Turning on single sign-on makes it compulsory. The panel states "Your team members will be mandatorily required to sign in via SSO to access this site."

### Google

1. Click the **User Profile** menu, then select **Security (SSO)** under **Organization Settings**.

2. Turn on the toggle on the **Google** widget. You and your teammates can then sign in with Google from the next sign-in onwards.

The toggle is unavailable unless you're signed in to G Suite. The panel offers a link to sign in.

### SAML providers

Okta, Azure, OneLogin, and Google Workspace all use SAML, so the exchange has the same 3 stages whichever you use.

1. Click the **User Profile** menu, then select **Security (SSO)** under **Organization Settings**.

2. Turn on the **SAML** widget to get its configuration values.

3. Create an application at the identity provider using those values.

4. Bring the provider's certificate and URLs back into Testsigma.

The terms the provider's own screens use:

- **Service Provider (SP)**: Testsigma.
- **Identity Provider (IdP)**: Okta, Azure AD, OneLogin, or Google Workspace.
- **Single Sign-On URL**: where authentication requests are sent.
- **Audience URI (SP Entity ID)**: the unique identifier for Testsigma, usually a URL.
- **Default RelayState**: where users land after authenticating.
- **Name ID Format**: the format of the user identifier in the assertion, usually an email address.
- **SAML or X.509 certificate**: verifies the identity of both parties in the exchange.

For Azure, the values Testsigma needs on the **Basic SAML Configuration** screen are:

```text
Entity ID:    https://id.testsigma.com/saml/<id>/metadata
Sign on URL:  https://id.testsigma.com/saml/<id>/callback
Relay State:  https://id.testsigma.com/
Logout URL:   leave empty
```

Replace `` with the SAML ID from your Testsigma SSO panel.

Users have to be assigned to the Testsigma application at the identity provider before they can sign in through it. Creating the application isn't enough. On Okta this is **Assign > Assign to People**, and on Azure it's **Assign users and groups** on the enterprise application.

## Sign in with SSO

1. Click **Sign in with SSO** on the Testsigma sign-in page.

2. Enter the email address configured with SSO for the account, then click **Sign in**.

The email address has to be configured for SSO first. Okta requires its mobile app for the first authentication.

## Turn off single sign-on

1. Turn off the **SAML** toggle.

2. Click **I Understand and Disable** in the warning prompt.

Disabling SSO removes the configuration rather than pausing it. Re-enabling means configuring the provider again from the start.

## What SSO changes

Once SSO is on, sign-in happens at your identity provider, so account lockout, password rotation, and any multi-factor requirement are governed there. The Testsigma password policy stops being the control that matters for those users.

## Related security controls

Three more controls sit outside this dialog.

- **Support access** grants the Testsigma support team temporary, logged, revocable access. See [Manage access](https://testsigma.com/docs/arcus/v2/settings/manage-access/).
- **Audit logs** record who changed what and when, including authentication and access events. See [Audit logs](https://testsigma.com/docs/arcus/v2/settings/audit-logs/).
- **IP whitelisting** lets Testsigma's cloud reach an application behind your firewall.

Roles decide what a signed-in user can do, and are assigned per project.
