Security holds four decisions: how people sign in, whether that is enforced, whether Learnient’s support staff may enter your account, and whether your own administrators may view the platform as somebody else.
Two of them have articles of their own. Setting up single sign-on covers connecting an identity provider, and Viewing the platform as somebody else covers the last switch on the screen.
Where it is
Section titled “Where it is”Choose Admin, then Workspace and Security.
Login method, and the fact worth knowing first
Section titled “Login method, and the fact worth knowing first”Login method chooses how people sign in: Password, Magic link or Passkey.
It locks after the first successful sign-in. Once anybody has signed in, the account’s login method cannot be changed from this screen, and changing it means contacting support.
So this is a decision to make while setting the account up, before inviting anybody — not one to revisit later. It is the only setting in Workspace that becomes unavailable simply because the account started being used.
Advanced security
Section titled “Advanced security”Advanced security adds a second factor on top of the login method: None, Two-factor authentication or Single sign-on.
Enforced method then decides whether that is optional or compulsory, from the same three choices. The screen describes it as restricting how users must sign in once your login method is active — so advanced security makes something available, and enforced method makes it the only way in.
A fourth option, Exclusive login method, appears here only when your login method is not Password. It makes the login method itself the sole route, rather than a second factor.
Set these in that order. Enforcing a method nobody has enrolled in locks people out, so make it available first, give people time, and enforce afterwards.
Moving an account to passkeys
Section titled “Moving an account to passkeys”Switching to passkeys is a rollout rather than a switch, because every person has to enrol a passkey of their own before it can work.
While one is running the screen shows Passkey rollout in progress with how many people have enrolled, and two controls: Finalise rollout and Cancel rollout.
Finalise makes passkeys the login method. Worth knowing: finalising does not lock the login method, so an account that moves to passkeys this way keeps the ability to change its mind.
Cancel stops the rollout and leaves the current method alone. Anybody who already enrolled keeps their passkey; they simply are not required to use it.
Letting Learnient support in
Section titled “Letting Learnient support in”Enable support access is the consent that allows Learnient’s own staff to enter your account to help with a case. With it off, they cannot.
Switching it on asks for an expiry duration, so the consent has an end rather than standing indefinitely.
Turning it off again ends every Learnient session in your account at once and withdraws consent for new ones. That is the control to reach for if you want support out now, rather than looking for a way to end one session.
Admin view-as
Section titled “Admin view-as”Allow admin view-as lets your own administrators who hold the View as permission see the platform as another person. The person is not notified, and every session is recorded in Audit logs.
That is a bigger decision than a switch suggests, and what a session can and cannot do is set out in How View as sessions are restricted and recorded.
What happens when you save
Section titled “What happens when you save”Save changes applies everything on the screen together. Changes to how people sign in take effect at their next sign-in rather than ending anybody’s current session.

