Security
Security settings cover your sign-in credentials and your organization’s password and single sign-on policy. They sit in one dialog reached from the User Profile menu, served from id.testsigma.com rather than the Arcus by Testsigma app, and they split into 2 groups. User settings cover your own account and are available to every user. Organization Settings apply to everyone in the account and need administrator access.
| Setting | Group | Who changes it |
|---|---|---|
| Profile | User settings | You, for your own account |
| Change Password | User settings | You, for your own account |
| 2FA | User settings | You, for your own account |
| Password Policy | Organization Settings | An administrator, for everyone |
| Security (SSO) | Organization Settings | An administrator, for everyone |
Your profile
Section titled “Your profile”-
Click the User Profile menu, then select Profile.
-
Edit your First Name and Last Name. Both are required.
-
Click Update.
Your email address appears alongside them and isn’t editable here, since it identifies the account. To change your profile picture, click the pencil icon on the avatar.
Change your password
Section titled “Change your password”-
Click the User Profile menu, then select Change Password.
-
Enter your Current Password.
-
Enter the new one in New Password.
-
Enter it again in Confirm Password.
-
Click Update.
Two-factor authentication
Section titled “Two-factor authentication”Two-factor authentication asks for a one-time code from an authenticator app alongside your password. You enable it for your own account, and you need an authenticator app installed before you start.
-
Click the User Profile menu, then select 2FA under User settings.
-
Turn on the Two-Factor Authentication toggle. The Confirm Your Password dialog opens.
-
Enter your password and click Continue.
-
In the Set Up Authenticator App dialog, scan the QR code or enter the setup key in your app, then click Continue.
-
Enter the 6-digit code from your authenticator app in Verify Authenticator App, then click Continue.
Password policy
Section titled “Password policy”The password policy sets 3 account-wide controls. Each is enabled separately, so you can use one without the others.
- Idle Session Timeout (minutes): signs an inactive user out after this many minutes.
- Max Failed Login Attempts: locks the account after this many consecutive failed sign-ins.
- Password Change Frequency (days): requires a new password after this many days.
To set them:
-
Click the User Profile menu, then select Password Policy under Organization Settings.
-
Click Configure.
-
In the Configure Password Policy dialog, select each setting you want to enable.
-
Enter the value for each one you selected.
-
Click Update.
Single sign-on
Section titled “Single sign-on”Single sign-on points authentication at your identity provider, so users sign in with existing corporate credentials and Testsigma accepts a secure token instead of a password.
Five providers are supported: Google, and the SAML-based Okta, Azure, OneLogin, and Google Workspace.
Only one SSO configuration can be active at a time, so enabling a second replaces the first. Verify a new configuration with one account before applying it to the organization.
-
Click the User Profile menu, then select Security (SSO) under Organization Settings.
-
Turn on the toggle on the Google widget. You and your teammates can then sign in with Google from the next sign-in onwards.
SAML providers
Section titled “SAML providers”Okta, Azure, OneLogin, and Google Workspace all use SAML, so the exchange has the same 3 stages whichever you use.
-
Click the User Profile menu, then select Security (SSO) under Organization Settings.
-
Turn on the SAML widget to get its configuration values.
-
Create an application at the identity provider using those values.
-
Bring the provider’s certificate and URLs back into Testsigma.
The terms the provider’s own screens use:
- Service Provider (SP): Testsigma.
- Identity Provider (IdP): Okta, Azure AD, OneLogin, or Google Workspace.
- Single Sign-On URL: where authentication requests are sent.
- Audience URI (SP Entity ID): the unique identifier for Testsigma, usually a URL.
- Default RelayState: where users land after authenticating.
- Name ID Format: the format of the user identifier in the assertion, usually an email address.
- SAML or X.509 certificate: verifies the identity of both parties in the exchange.
For Azure, the values Testsigma needs on the Basic SAML Configuration screen are:
Entity ID: https://id.testsigma.com/saml/<id>/metadataSign on URL: https://id.testsigma.com/saml/<id>/callbackRelay State: https://id.testsigma.com/Logout URL: leave emptyReplace <id> with the SAML ID from your Testsigma SSO panel.
Sign in with SSO
Section titled “Sign in with SSO”-
Click Sign in with SSO on the Testsigma sign-in page.
-
Enter the email address configured with SSO for the account, then click Sign in.
Turn off single sign-on
Section titled “Turn off single sign-on”-
Turn off the SAML toggle.
-
Click I Understand and Disable in the warning prompt.
What SSO changes
Section titled “What SSO changes”Once SSO is on, sign-in happens at your identity provider, so account lockout, password rotation, and any multi-factor requirement are governed there. The Testsigma password policy stops being the control that matters for those users.
Related security controls
Section titled “Related security controls”Three more controls sit outside this dialog.
- Support access grants the Testsigma support team temporary, logged, revocable access. See Manage access.
- Audit logs record who changed what and when, including authentication and access events. See Audit logs.
- IP whitelisting lets Testsigma’s cloud reach an application behind your firewall.
Roles decide what a signed-in user can do, and are assigned per project.
Was this page helpful?
Thanks for the feedback.