> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cymph.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Sign-up domains

> Limit who can create an account to e-mail addresses from approved domains.

Users with the On-prem Administrator role can limit who creates an account on their own to e-mail addresses from certain domains, such as your company's. It is **off by default**, so anyone can sign up until you turn it on.

## How to limit sign-up to domains

1. Go to the **On-prem settings** page
   * Click on **On-prem** from the navigation menu, then **Settings**
2. Open the **Authentication** tab and click **Configure** on **Sign-up Domains**
3. Turn on **Limit sign-up to these domains**
4. Type each allowed domain, for example `acme.com`, and press Enter
5. Click **Update Settings**

## What is limited

* **Sign-up with e-mail and password**: an address from a domain that is not allowed cannot create an account. The sign-up page displays a general error.
* **Sign-up with [SSO](/deployment/settings/sso)**: Google, GitHub or Microsoft Entra ID cannot create an account for an address from a domain that is not allowed. With SSO, the account is created the first time the user signs in.

An allowed domain also covers its subdomains: `acme.com` allows `jane@eu.acme.com`, but not `jane@notacme.com`.

## What is never blocked

* Users who already have an account, including when they sign in with SSO.
* Accounts the on-premises administrator creates.
* Anyone with a pending invitation to an organisation, whatever their domain. This is how an organisation brings in an outside contractor.

<Info>
  Turned on with no domains, only invited people can sign up.
</Info>
