SSO & MFA

This guide covers how your team signs in to TYO Reach and how to raise the bar on account security for the whole group. It's written for group owners deciding how members authenticate, and for members who want to know what to expect when they sign in.

Single sign-on

Members can sign in to TYO Reach with their existing Google or Microsoft account — both are available today, no setup required on your side. There's no separate TYO password to create or manage; sign-in uses your identity provider's own login flow.

Behind the scenes, sign-in is backed by id.tyo.com.au, TYO's own identity service. Sessions use short-lived tokens, and long-lived credentials are never stored in the client app.

Multi-factor authentication

TYO Reach supports multi-factor authentication via TOTP (time-based one-time passwords) — any authenticator app that implements RFC 6238 works, including the common ones most people already have installed.

As a group owner, you can require MFA for all members of your group. Once that policy is turned on, it applies to everyone in the group — members can't opt out of a group-enforced MFA policy on their own account.

Enterprise directory federation

If your organisation federates its own identity provider — Azure AD / Entra ID, or another OIDC-compatible directory — TYO Reach can support directory federation for your group. This is available on request rather than as a self-serve setting, so we can configure it correctly for your directory. Get in touch and we'll help you set it up.