Skip to main content

Security Tab

The Security Tab contains global firm settings for Two-Factor Authentication, Single Sign On, and Approved Domain List.

NOTE: You must have Enabled and Modify permissions to General > Firm Preferences to make global changes.

Refer to Two-Factor Authentication By Firm for details on configuring 2FA for all users in your firm from this global setting.

Single Sign On

Neos now includes the ability to globally control how your firm's users are logging into Neos. Users now have the option to log in with their Microsoft 365 account or their Neos username and password. This setting will be hidden by default. To access Single Sign On, contact Support to start the process of provisioning this feature.

Using the Single Sign On slider, your firm's Neos administrator can choose to have all users sign in to Neos with only their Microsoft 365 account OR present them with both options (Neos or Microsoft). The Microsoft option allows users to be automatically authenticated when they are signed in to Microsoft 365. Users who are not currently signed in will be prompted to enter their Microsoft 365 email and password and then authenticated using their linked phone number to verify their identity.

When the slider shows 'Single Sign On is turned ON', all users in your firm MUST use their Microsoft 365 account to log into Neos.

NOTE: Staff must have their email address saved to their Staff Profile in order to log in to Neos using the Sign in with Microsoft option. Before enabling the Single Sign On slider globally, the Firm Administrator should check to ensure that ALL users that sign in to Neos have their email saved to their Staff Profile.

The Change Email Address button will be disabled for all non-Neos Admin users when Single Sign On is turned ON (even if they have enabled permissions to the Staff Directory).

If your firm uses resource calendars and/or the CasePulse integration, the Microsoft Single Sign On should continue to seamlessly function. Contact Support if firm calendars are not updating when forcing staff to sign in to Neos using Microsoft 365.

When the slider shows 'Single Sign On is turned OFF' all users will have the option to log in to Neos using either their Microsoft 365 account or their Neos account credentials.

Whether or not your firm enforces Single Sign On, you can use the direct url to login through Microsoft: https://app.neos-cloud.com/SignInWithMicrosoft?companyId=[firm's company ID]. This will lead you to sign in with your Microsoft account as our identify provider rather than taking you to the login page. This direct url can also be used to configure other custom login solutions, such as Okta, as long as they are paired with Microsoft 365 as the identity provider.

Approved Domain List

The Approved Domain List allows firms to have greater security over which users can access Neos, mitigating any potential risks. This list restricts logins to only the domains that have been explicitly verified and authorized by your firm. The Approved Domain List is especially essential for firms that user multiple domains.

Select the slider to access the list of approved domains. Assembly Software will be automatically listed as an approved domain, which enables Neos Support to access your firm's Neos, when such access is explicitly granted.

Click the + button to add additional, unique approved domains. You do not need to enter the protocol identifier (https://) when adding new domains. Up to 255 characters can be entered, not including the domain extension (e.g., .com).

Any listed domain can be removed by clicking the trash can icon. Confirm your intention by clicking Yes on the Delete item message box.

Click the Save button to keep your changes.

Did this answer your question?