> ## Documentation Index
> Fetch the complete documentation index at: https://docs.resolve.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Sign-in enforcement

> Restrict sign-in to people in your synced directory, after reviewing exactly who gains and loses access.

Directory sync keeps your user list current. Sign-in enforcement decides whether people outside that list can sign in at all.

Sign-in enforcement is **off until you turn it on**. ResolveAI shows you the access change before you enable it, and the confirm button names the consequence.

<Info>
  You must enable sign-in enforcement yourself. Groups become linkable as soon as they are pushed.
</Info>

## Before you turn it on

ResolveAI builds the comparison only when:

* Sync health is **healthy**. If the last push failed, fix the connection first so the comparison uses the current directory.
* The directory must contain at least one active user.
* Enabling must not remove every admin.

If sync health is degraded you will see **Needs attention: the last directory push failed**, with the reason.

## Review the change

On **Admin → Authentication**, find **Sign-in enforcement** and start the review. ResolveAI computes the comparison and opens **Review access changes**.

The dialog shows how many people can sign in today and groups the changes by category:

| Category       | Who is in it                                       |
| -------------- | -------------------------------------------------- |
| **Removals**   | People who can sign in today and would lose access |
| **Additions**  | People in the directory who would gain access      |
| **Unaffected** | People who keep access either way                  |

The dialog marks admins who would lose access.

The confirm button names the outcome. If nobody loses access, it reads **Enable sign-in enforcement**. Otherwise it reads **Remove N users and enable sign-in enforcement** and is styled as a destructive action.

<Warning>
  **The lists include only people ResolveAI already knows about.**

  The lists show who gains access, loses access, or stays unchanged among current users. They cannot include someone who would otherwise be created on first sign-in, because that person is not in the directory or the current roster.

  Read the comparison as "who is affected among people we already know about." It is not the complete set of affected people. Turning enforcement on also ends just-in-time creation for everyone else at your domain.
</Warning>

If the directory changes after ResolveAI builds the comparison, ResolveAI refuses the confirmation. Start the review again.

## Turning it off

The same section offers **Turn off sign-in enforcement**. People outside the directory can sign in again, and just-in-time creation resumes.

If a push fails while enforcement is on, enforcement stays on. A broken directory does not reopen sign-in. The imported directory stays stale until your provider pushes again.
