Skip to content
English
  • There are no suggestions because the search field is empty.

Why verifying a domain can lock members out

 

For Organization Admins

What happens when you verify a domain

Once a domain is verified, everyone on that domain becomes a managed member of your organization. From that point on, they can only sign in with the methods your organization allows.

Before verification, sign-in restrictions don't apply to them. That's why verifying can suddenly lock people out.

Who loses access

The warning ({N} members will lose access) counts members on the domain whose only sign-in methods are ones your organization has disabled. For example, they sign in with Google, but your organization only allows SSO.

If your organization allows email code (OTP) sign-in, the count is always 0, because anyone can fall back to a code sent to their email.

What affected members will see

They'll be signed out shortly after verification, and asked to sign in again with an allowed method. Their documents are not deleted. However, if their new sign-in lands in a different account, they may not see their existing documents. Contact us if that happens.

Before you verify

  • Review your allowed methods under Authentication & Identity → Authentication
  • Consider enabling email code (OTP) during the transition so no one gets locked out
  • Let your team know which sign-in method to use
  • Heads up: once your DNS record is set up, verification completes automatically within about an hour, so adjust sign-in settings first

Why verification is sometimes paused

Goodnotes won't complete a verification that would lock out all of your admins, because no one would be left to fix the settings. If you see "verification paused", enable a sign-in method one of your admins uses (or email code) and it will resume automatically.

Need help?

Unsure how a change affects your team? Contact us before verifying.