Skip to main content
Name two owners before you restrict how your team signs in: the person who administers your Google Workspace or Microsoft Entra directory, and the person who owns the TWICE Commerce account. They are rarely the same person, and access breaks in the gap between them. Settle it now rather than in the week before you go live. Getting a group created in your directory, or agreeing who approves an access request, goes through an IT department on its own timetable.

What restricting sign-in actually does

TWICE Commerce does not federate with your identity provider. There is no SAML or OIDC connection to your directory and no directory sync. What the admin gives you is an allowlist of four sign-in methods: Email & Password, Google, Microsoft and Facebook. Restrict the account to Microsoft, and everyone reaches it with a Microsoft account that Microsoft has authenticated. Nothing about your directory’s groups, policies or joiners reaches TWICE Commerce with it.

Who decides what

Your directory decides who gets through the door. TWICE Commerce decides what they can touch once inside. Both have to happen, and only one of them is ours. Revoking someone in your directory stops them signing in with that provider. It does not end their TWICE Commerce membership, and it does not change what their role allowed. A leaver has to be removed in both places.

Decide these four things

Answer all four before anyone changes a setting. Each one has an owner on your side, and none of them is a TWICE Commerce setting. Write the two names down where the launch owner can find them. A rota or a shared mailbox is not an owner.

Restrict the sign-in methods

Set the allowed methods under Settings → Security, in the Sign-in methods card. Tick every method your team is allowed to use and clear the rest. A new account allows all four until you restrict it. At least one method has to stay selected: the form refuses to save an empty set, with “At least one sign-in method is required”. Tell the team before you save. Anyone signed in with a method you cleared is dropped to the account picker on their next request, and their row there reads “Sign in with Microsoft to access” rather than opening.
Restricting sign-in methods is a plan capability. The plans list enforced SSO sign-in under Enterprise. Check your agreement, or ask your TWICE Commerce contact what your account includes.

What happens to people who already have a password

Nobody is locked out of their work, and no data moves. Each person links their directory account to the membership they already have, once. Microsoft accounts can skip the emailed code when their email domain is on the account’s verified login domains. That list has no field in the admin, so ask your TWICE Commerce contact to set it before a large team links up.

Keep a way back in

Turn on Security restrictions bypass in the same view, and check that at least two people can use it. It lets a user who holds the Account settings > Security > Manage permission sign in with email and password even when that method is not allowed, which is how a misconfigured provider gets fixed. Owner and Admin hold that permission. Manager and Member do not, and neither does a custom role that was not given it. Test the bypass while the restriction is live, not after an outage starts. Have one of those two sign out, sign in with email and password, and confirm they reach the admin. Without the bypass, a misconfigured provider leaves nobody able to change the setting, and recovering the account becomes a support request.

Roles are never driven from your directory

Assign every role in TWICE Commerce by hand, under Settings → Users & Roles. There is no group-to-role mapping and no provisioning from your directory, so a group in Entra changes nothing here. Plan the two processes around that:
  • A joiner needs an account in your directory and an invite in TWICE Commerce. Neither implies the other, and the invite carries the role.
  • A leaver needs removing in both places. Their directory account going away blocks that provider, but their membership survives it, and so does a password they set earlier if Email & Password is still allowed.
Remove a leaver under Settings → Users & Roles, or set them to Suspended to keep the record and end the access. The account owner cannot be suspended or removed, so transfer ownership first when the owner is the one leaving. See Get your team into TWICE for choosing the role itself.

What TWICE support cannot do

Ask your own IT department for anything on the left. Nobody at TWICE Commerce can reach your directory, and asking costs you a round trip.

Done when

  • One named person owns admin access on your side, and one named person administers the directory. The launch owner has both names.
  • Your joiner and leaver steps name both systems, and someone has agreed to run them.
  • The allowed sign-in methods match what your team can actually use, and the team was told before it changed.
  • Two people hold the security permission, and one of them has signed in through the bypass with the restriction live.

Set up your business

The launch step this guide belongs to.

Get your team into TWICE

Choosing a role, sending the invite, and visible areas versus data access.

Security settings

The two cards on the page, field by field.

Users & Roles settings

The invite flow, the four system roles, and the permissions matrix.

Before you start

The decisions that come before any configuration.