Skip to main content

Protect your account with 2FA, Google Sign-On or SAML SSO

Use this article to set up and manage authentication for your Intercom workspace — including enabling Google Sign-In, requiring Two-Factor Authentication (2FA), switching between login methods, and troubleshooting common login issues.

Written by Penny Gray

To help keep your Intercom workspace secure, we offer several authentication options for teammates. These methods help prevent unauthorized access, reduce the risk of phishing attacks, and give you better control over how your team signs in.

Workspace admins with permission to access general and security settings can configure authentication methods for all teammates. Individual teammates can manage their own 2FA from their personal account settings.

You can configure the following authentication methods for your workspace:

  • Google Sign-In — Let teammates log in with their Google Workspace accounts

  • Two-Factor Authentication (2FA) — requires teammates to enter a one-time code from an authenticator app in addition to their password

  • SAML Single Sign-On (SSO)Enforce authentication via your identity provider (Enterprise only)

Note: Turning off email and password login is strongly recommended. Passwords are the most common entry point for attackers. They're prone to phishing, reuse, and weak security practices. Use SSO and/or Google Sign-In with 2FA to provide stronger protection for your workspace.

You should disable email and password logins by toggling off Email & Password under Settings > Workspace > Security > Authentication methods.

The Authentication methods section shows toggle options for Email & Password, Require Google sign in, and Require SAML.

How do I set up authentication for my workspace?

Go to Settings > Workspace > Security and choose the option you’d prefer under "Authentication methods".

Note: You must have permission to access general and security settings to enable this. Once you require Google SSO or SAML, make sure to disable email and password logins.

The table below compares the four available authentication methods for Intercom workspaces, including plan availability, whether workspace-wide enforcement is supported, and relative security strength.

Method

Availability

Enforcement

Security

Email & Password

All plans

N/A

❌ Poor

Email & Password w / 2FA

All plans

Can be enforced

✅ Improved

Require Google sign in

All plans

Can be enforced

✅ Strong

Require SAML

Can be enforced

✅ Strong

Note: Once you require Google SSO or SAML, make sure to disable email and password logins to prevent teammates from bypassing SSO.

How do I set up Two-Factor Authentication (2FA) for my workspace?

If you have to let your users log in with email and password, you can add an extra layer of security with two-factor authentication. Teammates supply a unique code from an authenticator app like Google Authenticator or Authy on login.

  • Available on all plans

  • Can be enforced workspace-wide

  • Each teammate sets up their own device

Note: If teammates have not already set up 2FA when you enable this for your workspace, they'll be prompted to set it up on their next login. They'll need to scan a QR code using an authenticator app such as Google Authenticator or Authy, and won't be able to proceed until setup is complete.

How do I enable Google Sign-In for my workspace?

Google Sign-In lets teammates log in with their Google Workspace accounts. Once enabled, teammates will be prompted to sign in with Google on their next login. Ensure all teammates have a Google account using an email address that matches their Intercom account before enforcing this method workspace-wide.

  • Available on all plans

  • Easy to enable from your security settings

  • Optional domain restriction — you can limit sign-in to a specific domain (e.g. only @yourcompany.com addresses). Configure this in the Google Sign-In settings after enabling it.

How do I set up SAML SSO for my workspace?

SAML SSO (Security Assertion Markup Language Single Sign-On) allows your team to log in via your Identity Provider (IdP — a service that manages your team's logins, such as Okta, Azure AD, or OneLogin). This option is available on Enterprise plans only.

  • Available on Enterprise plans

  • Supports Just-in-Time (JIT) provisioning — teammate accounts are created automatically on their first login — and SCIM (System for Cross-domain Identity Management) for automated account provisioning and deprovisioning

  • Requires DNS domain verification and Identity Provider (IdP) configuration

How do I require SAML SSO with an identity provider?

Integrating Intercom with an identity provider like Okta or OneLogin is the most secure and simple way for your team to log in.

Follow the steps in this article to configure your identity provider, to require SAML SSO (Single Sign On) from all your teammates, or offer it as one of your sign in options.


Switching between authentication methods

How do I switch from Google SSO back to email and password login?

To switch back to email and password login, go to Settings > Workspace > Security > Authentication methods, toggle off Require Google sign in, and toggle on Email & Password.

Note: Teammates who originally signed up via Google SSO may not have a password set. They'll need to use the "Forgot your password?" link on the login page to create one before they can sign in with email and password.

How do I switch from email and password login to Google SSO?

To switch to Google SSO, go to Settings > Workspace > Security > Authentication methods and toggle on Require Google sign in. Once all teammates have confirmed they can sign in with Google, disable email and password login to strengthen your workspace security. Ensure all teammates have a Google account using an email address that matches their Intercom account before enforcing this method workspace-wide.

What should I do if a teammate's SSO stops working after a company email domain change?

If a teammate's company has recently changed its email domain (for example, from example@olddomain.com to example@newdomain.com), they may see this error when accepting a workspace invite:

"No active invite with your email address exists for this workspace. Invites can only be redeemed by the exact email address to which they were sent."

This is usually caused by an SSO token mismatch. An SSO token is the unique identifier that links your Intercom account to your Google account. If your company has recently changed its email domain, your SSO token is still linked to your old address. Contact Intercom Support — they can unlink the SSO token from the old address so the teammate can sign in with their updated email.

How does Intercom protect against suspicious logins?

Intercom continuously monitors login activity and automatically protects teammate accounts. If a suspicious email/password login is detected, email verification will be required before login can be completed. This includes:

  • Intelligent Login & Session Protection: Extra verification for unusual login patterns and advanced measures against abuse.

  • Security Notifications: Timely alerts about potential security events.

The teammate will receive a verification email like so and will have to enter the unique verification token before they can proceed.

The verification email screen shows a field for the unique verification token sent to the teammate's registered email address.

How do teammates manage their own authentication settings?

How do I enable 2FA on my individual Intercom account?

You can enable 2FA on your own Intercom account, separate from the settings of any workspace you're a member of.

  1. Log in to your Intercom account.

  2. In the Two-Factor Authentication section, click Enable 2FA.

    The Two-Factor Authentication (2FA) section in Account security settings, showing the Enable 2FA toggle in the off state.
  3. Scan the QR code displayed on the screen using your authenticator app (e.g., Google Authenticator or Authy).

  4. Enter the 6-digit code generated by the app to complete the setup.

  5. Download and securely store the recovery codes provided during setup. 2FA is now active — you'll be prompted for a code from your authenticator app on your next login.

A QR-based system is used to set up an authenticator app. Intercom is compatible with popular authenticator apps like Google Authenticator and Authy.

Teammates with 2FA enabled for their account should download their individual Recovery Codes by going to Settings > Personal > Account security. Once there, if 2FA is enabled, they should see a link they can click to download these codes.

Important: You should generate and securely save your recovery codes to avoid potentially being locked out of your account.

Recovery codes are especially useful if you encounter issues with your authenticator app or lose access to your device. If your recovery codes are missing or not working, you can request a new recovery code to be sent to your registered email. Use this code to log in and reset your 2FA connection by disabling and re-enabling 2FA in Settings > Personal > Account security.

The Account security settings page shows the Recovery Codes section with a link to download your codes.

Note: If you created your account with Google sign-on, you won't see an option to set up 2FA unless you set a password. You can do this by going through the password reset flow, using the 'Forgot your password?' link on the login page. Configure or disable 2FA under your account settings after regaining access.

How do I disable 2FA on my personal Intercom account?

To disable 2FA on your personal Intercom account, follow these steps:

  1. In the Two-Factor Authentication (2FA) section, toggle off Enable 2FA.

  2. Toggle off 2FA. Depending on your account setup or workspace policies, you might need a recovery code to complete this process. Once disabled, you won't be prompted for a verification code on your next login.

Note: Personal 2FA settings apply only to your individual login. If 2FA is enforced workspace-wide, you won't be able to disable it from your personal settings — contact your workspace admin.

How do workspace admins manage 2FA across the workspace?

Workspace admins cannot change personal 2FA settings for individual teammates, but can enforce 2FA workspace-wide. When enforced, teammates are prompted to set up 2FA on their next login. For workspace-level settings, go to Settings > Workspace > Security.

How do I migrate my authenticator app to a new device?

To migrate 2FA to a new device, you must disable and re-enable it. Follow these steps:

  1. Toggle off Enable 2FA under "Two Factor Authentication (2FA)".

    The 2FA setup screen shows the Enable 2FA toggle in the on state with a QR code to scan using your authenticator app on your new device.
  2. After disabling 2FA, toggle it back on to set it up with your new phone.

  3. Scan the QR code displayed on your computer screen using the authenticator app on your new phone.

  4. Enter the 6-digit code shown in your authenticator app to confirm the new device pairing and complete setup. 2FA is now active on your new device.

How do I troubleshoot 2FA issues?

Why are my authenticator app codes not working?

If your authenticator app codes are not working, try the following:

Device settings and app synchronization:

  • Ensure your mobile device’s time and date settings are set to "Set Automatically," as discrepancies can cause codes to fail.

  • Restart your mobile device to re-sync the time settings of your authenticator app.

  • Enable automatic time synchronization in your device's time settings to ensure the authenticator app works correctly.

App Reconfiguration:

  • Reset your 2FA connection by disabling and re-enabling it in Settings > Personal > Account security. Then, scan a new QR code using your authenticator app.

  • If possible, use a different authenticator app as a backup.

What should I do if I can't disable 2FA?

If you're unable to disable 2FA on your account, try the following:

  • Use a recovery code: Recovery codes are often emailed to you during initial 2FA setup. Enter the recovery code on the 2FA login page to regain access.

  • Check workspace policies: If your workspace enforces 2FA for all teammates, contact your administrator to address this.

Why am I still being asked for a 6-digit code after disabling 2FA?

If you've disabled 2FA but are still being prompted for a code, follow these steps:

  • Log in using a recovery code.

  • Go to Settings > Personal > Account security and confirm that 2FA is toggled off.

  • If 2FA remains active due to workspace settings, contact an administrator for further assistance.


How do I help a teammate who has lost their 2FA device?

A teammate with the 'Can manage teammates, seats, and permissions' permission can send a recovery code to the locked-out teammate's registered email address. If recovery codes fail, the administrator can reset the failed login attempts and issue a new recovery code. Follow these steps:

  1. Have a teammate with the 'Can manage teammates, seats, and permissions' permission go to Settings > Workspace > Teammates.

  2. Click the 2FA Recovery button next to the locked-out teammate's account. A recovery code will be sent to their registered email address.

  3. On the 2FA login page, select Enter a recovery code and enter the code from the email to regain access.

What should I do after recovering access to my account?

After using a recovery code to regain access following a 2FA lockout, 2FA will still be enabled. To prevent future disruptions, complete the following steps:

  1. If needed, toggle off 2FA from your preferences to disable it temporarily.

  2. Re-enable 2FA and set it up with an authenticator app on a new or existing device. Download additional recovery codes from your account settings for future use.

To prevent future lockouts, keep these best practices in mind:

  • Always store recovery codes securely after initial setup.

  • Pair multiple devices with your 2FA setup where possible.

  • Regularly update your 2FA settings to reflect changed devices or preferences.


Why am I not receiving my verification code or login email?

If you're not receiving a verification code or login email, try the following:

  • Delayed Verification Codes: Use the most recent code received as long as it hasn’t expired. If expired, request a new code and use it immediately.

  • Codes Not Working in Mobile App: Ensure you enter the latest code and correct your mobile device’s time and date settings to prevent mismatches. Restart the app and try the code again.

  • Authenticator App Errors: If the authentication code generated by your app is consistently rejected, consider reconfiguring the app or switching to another.

  • Check email settings: Look in your spam, junk, or promotions folders to ensure emails from Intercom are not being filtered or delayed.


What should I do if my SSO stops working after an email domain change?

If you see the following error message:

"​No active invite with your email address exists for this workspace. Invites can only be redeemed by the exact email address to which they were sent. If you think you're using the right email to redeem an invite, please contact your admin for help."

This is usually caused by an SSO token mismatch. An SSO token is the unique identifier that links your Intercom account to your Google account. If your company has recently changed its email domain, your SSO token is still linked to your old address.

For example changing your email from example@olddomain.com to example@newdomain.com.

In Intercom, your SSO token will still be attached to your old email address. When you attempt to log in with Google SSO using a new invite, it's still linked to the old domain. This triggers the error "Invites can only be redeemed by the exact email address to which they were sent."

To resolve this, reach out to Intercom Support who can unlink the SSO token from your old email address, allowing you to use Google SSO with your updated address.


What happens if I update the email address on my Google account?

If you are updating an existing Google account with a new email, there will be no issues. Intercom maps teammates to Google accounts by storing their Google account ID — not the email address.

If something goes wrong, you can always use email and password to gain access (if your workspace allows email/password as login method). Note: It's possible your teammates don't have passwords set as they used Google SSO to redeem invites. In that case they can log out of Intercom and set their password here.


💡Tip

Need more help? Get support from our Community Forum
Find answers and get help from Intercom Support and Community Experts


Did this answer your question?