With domain control enabled on your Lucid account, users are prevented from creating unauthorized accounts with the controlled domain. Domain control settings can be found in the Security section of the Lucid admin panel.
For information about additional security features, check out our Lucid admin panel: Security settings article.
Plan availability: Enterprise only.
- Available on FedRAMP accounts.
- Domain control and domain verification are Enterprise only. Domain invites are available to Team plans.
- Read the Lucid Plans article for more information about what is available on your account or the Upgrade your Lucid account article for instructions to upgrade.
Enable Domain Control
Domain Control is an Enterprise only feature that allows you to control the security settings for users on your domain and set security standards for your entire organization. With domain control enabled on your Lucid account, users are prevented from creating unauthorized accounts with the controlled domain.
When you enable domain control, users who attempt to sign up for a Lucid account will be notified that an Enterprise account already exists and will be redirected to verify their identity. Once they verify their identity, they’ll be added to your organization’s Lucid account.
The method you select to verify users' identities should match the default user sign in authentication method set for the account.
Select one of the following options for verifying user identity:
- Confirmation email: The user receives an email with a confirmation link.
- SAML authentication: The user is redirected to your organization’s SAML instance.
- Google SSO authentication: The user is redirected to authenticate via Google SSO.
- Office 365 SSO authentication: The user is redirected to authenticate via their Office 365 credentials.
- Redirect to custom authentication URL: The user is redirected to a different SSO provider via an authentication URL.
Note: Due to the security demands of domain control, you will need to contact your Account Manager, Customer Success Manager, or contact sales to request setup.
Domain verification
Domains are verified for two purposes—consolidations and domain control.
Domain verification is a process that confirms ownership of specific domains prior to locking down a domain to be controlled by a single account or consolidating users who are on those domains. For security and data privacy reasons, Lucid is obligated to follow a specific procedure to verify that an account who's asking to consolidate or control a specific domain does own that domain.
Domain verification must occur if both of the following are true:
- The domain to be consolidated or controlled is different from the account owner's domain (referring to their email address on the account).
- There are no users on the account with the same domain as the one to be consolidated or controlled.
Domain verification methods
Lucid offers four ways to verify your domain:
- DNS Record Validation
- Signed Form Validation
- Hosting Validation
- Email Validation
To request a domain verification for your Enterprise account, contact your Account Manager, Customer Success Manager, or contact sales and provide the following details:
- The domain(s) to be verified.
- Email address(es) and name(s) of the web-administrators of those domains (if verifying domain via Hosting or DNS Record Validation).
- Email address(es) and name(s) of the Lucid admin(s).
Domain invites
Determine whether users on your Team or Enterprise account on the same domain can email you a request to join your account when they create a Lucid account. If you uncheck this box, you will no longer receive join requests and the next largest account with the same domain will receive the requests.
Determine whether users on your account can leave by accepting an invitation to another account. Allowing users to leave your account without express action from an admin is defaulted to off. Selecting that option will allow your users to accept explicit invites from other accounts.
Note: If a user leaves your account via an invitation, they will by default take their documents with them. However, if their documents are organized within a team folder, the documents will not be transferred with the user.
Allow non-admins to invite new users
With this setting, you can indicate the ability for non-admin users on your Team or Enterprise account to invite new users to join.
Your options include:
- No restrictions. All users can invite new users.
- All users can invite other users with the same—or approved—domains.
- All users can invite new users from domains listed here.
- Total lockdown. Only the account owner, account admins, and Shield admins can invite new users.
Give feedback on this article
Have feedback about this article? Tell us about your experience here.