> For the complete documentation index, see [llms.txt](https://support.docstudio.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://support.docstudio.com/use-cases/how-to-choose-an-authorization-method.md).

# How to Choose an Authorization Method

{% hint style="info" %}
Use this page when you know who needs access to DocStudio, but you have not chosen the access method yet.
{% endhint %}

### Before you start

Before you choose a method, define:

1. Who needs access.
2. Whether access is personal or company-managed.
3. Whether the user signs in directly or through a third-party provider.
4. Whether the company requires SSO.
5. Whether MFA is needed.
6. Whether access is needed for the interface or for API requests.

Then use the table below to choose the method and open the related instruction.

### What users often confuse

* Google sign-in is not the same as Google SSO setup.
* Microsoft / Azure sign-in is not the same as Azure SSO setup.
* MFA is not a primary sign-in method.
* Application tokens are not used for interactive sign-in.

### Choose the right method

<table><thead><tr><th>User task</th><th width="181">Use</th><th width="190">Avoid</th><th>Go to</th></tr></thead><tbody><tr><td>Sign in with a standard DocStudio account</td><td>Email and password</td><td>SSO or provider sign-in when the user does not use that setup</td><td><a href="/spaces/oqUiFHjwtCCGSaEDqbXb/pages/KwZ1B5WwKB9JgVmNX9cz">How to Sign In to DocStudio</a></td></tr><tr><td>Sign in with Google</td><td>Google sign-in</td><td>password reset when the issue is with Google authorization</td><td><a href="/spaces/oqUiFHjwtCCGSaEDqbXb/pages/KwZ1B5WwKB9JgVmNX9cz">How to Sign In to DocStudio</a></td></tr><tr><td>Sign in with Microsoft or Azure</td><td>Microsoft / Azure sign-in</td><td>Azure SSO setup when the user only needs the Microsoft sign-in button</td><td><a href="/spaces/oqUiFHjwtCCGSaEDqbXb/pages/KwZ1B5WwKB9JgVmNX9cz">How to Sign In to DocStudio</a></td></tr><tr><td>Sign in with Apple ID</td><td>Apple sign-in</td><td>password reset when the issue is with Apple authorization</td><td><a href="/spaces/oqUiFHjwtCCGSaEDqbXb/pages/KwZ1B5WwKB9JgVmNX9cz">How to Sign In to DocStudio</a></td></tr><tr><td>Sign in through a company identity provider</td><td>SSO</td><td>Google, Microsoft / Azure, or Apple sign-in when the company requires SSO</td><td><a href="/spaces/oqUiFHjwtCCGSaEDqbXb/pages/KwZ1B5WwKB9JgVmNX9cz">How to Sign In to DocStudio</a></td></tr><tr><td>Configure company SSO with Azure</td><td>Azure SSO setup</td><td>Microsoft / Azure sign-in when the task is company SSO configuration</td><td><a href="/spaces/oqUiFHjwtCCGSaEDqbXb/pages/eo2MZ96mN9IzD5PTMwVy">How to set up SSO SAML 2.0 with Azure</a>, <a href="/spaces/oqUiFHjwtCCGSaEDqbXb/pages/WeoRDdCgmuXvCj9Of8JP">How to set up SSO OAuth 2.0 with Azure</a></td></tr><tr><td>Configure company SSO with Google</td><td>Google SSO setup</td><td>Google sign-in when the task is company SSO configuration</td><td><a href="/spaces/oqUiFHjwtCCGSaEDqbXb/pages/SmysIQtdBbxKfKx0Xqkv">How to Set Up SSO with Google</a></td></tr><tr><td>Add extra verification during sign-in</td><td>MFA</td><td>MFA as the main sign-in method</td><td><a href="/spaces/oqUiFHjwtCCGSaEDqbXb/pages/1mVRY7Htq9r8XCGkcWVQ">Personal Settings Page Overview</a></td></tr><tr><td>Control password requirements</td><td>Password policy</td><td>manual password rules outside account settings</td><td><a href="/spaces/oqUiFHjwtCCGSaEDqbXb/pages/FDPEUvHU7wi1ChzxEfAv">Password Rules</a>, <a href="/spaces/oqUiFHjwtCCGSaEDqbXb/pages/iMh6ymhdLDQu1L7XnCWz">How to Configure Password Policy</a></td></tr><tr><td>Authorize API requests</td><td>Application tokens</td><td>application tokens for regular user sign-in</td><td><a href="/spaces/oqUiFHjwtCCGSaEDqbXb/pages/mlWRuxFtiDB2fxGoofnt">Application Tokens (API Access)</a></td></tr><tr><td>Manage automated access</td><td>Integrations and API access</td><td>password sharing or manual sign-in for API flows</td><td><a href="/spaces/oqUiFHjwtCCGSaEDqbXb/pages/RzR2M5kCMC1DXtCeA2SQ">Integrations &#x26; API Access</a>, <a href="/spaces/oqUiFHjwtCCGSaEDqbXb/pages/mlWRuxFtiDB2fxGoofnt">Application Tokens (API Access)</a></td></tr></tbody></table>

After you choose a method, use the scenarios below to confirm the correct flow.

### Typical scenarios

#### Sign in a personal account

**Goal:** Access a personal DocStudio account without company-managed SSO.

**Use:**

* email and password
* Google sign-in
* Microsoft / Azure sign-in
* Apple sign-in

**Do not use:**

* SSO when the user does not belong to a company SSO setup
* application tokens for interface access
* admin SSO setup instructions for a personal sign-in issue

**Go to:**

* [How to Sign In to DocStudio](/user/authorization-and-security/how-to-sign-in-to-docstudio.md)
* [Password Rules](/user/authorization-and-security/password-rules.md)
* [How to Change Your Password](/user/user-profile/how-to-change-your-password.md)

#### Sign in as a corporate user

**Goal:** Access a company workspace with the configured company method.

**Use:**

* email and password, if the company allows it
* Google sign-in, if the company uses it
* Microsoft / Azure sign-in, if the company uses it
* SSO, if the company requires it

**Do not use:**

* personal account registration when the user must access company data
* application tokens for interface access
* password reset as the only fix when the company requires SSO

**Go to:**

* [How to Sign In to DocStudio](/user/authorization-and-security/how-to-sign-in-to-docstudio.md)
* [Account Invites Overview](/user/user-profile/account-invites-overview.md)
* [Access Levels](/user/user-access-and-permissions/access-levels.md)
* [Account Permissions](/user/user-access-and-permissions/account-permissions.md)

#### Choose the correct invitation flow

**Goal:** Start the correct first login flow from an invitation.

**Use:**

* the standard sign-in flow, if the invite is for regular account access
* the company SSO flow, if the invite is tied to company SSO
* the company-configured provider flow, if the company uses it

**Do not use:**

* password reset before you confirm the expected access method
* personal registration when the invite is for a company workspace
* application tokens for first login

**Go to:**

* [Account Invites Overview](/user/user-profile/account-invites-overview.md)
* [How to Sign In to DocStudio](/user/authorization-and-security/how-to-sign-in-to-docstudio.md)

#### Sign in with a third-party provider

**Goal:** Sign in through Google, Microsoft / Azure, or Apple.

**Use:**

* Google sign-in
* Microsoft / Azure sign-in
* Apple sign-in

**Do not use:**

* SSO setup instructions when the user only needs a provider button
* password reset when the problem is with the provider flow
* application tokens for user sign-in

**Go to:**

* [How to Sign In to DocStudio](/user/authorization-and-security/how-to-sign-in-to-docstudio.md)

#### Sign in through SSO

**Goal:** Access DocStudio through company-managed authentication.

**Use:**

* SSO on the sign-in page
* the SSO invitation flow
* the company identity provider flow

**Do not use:**

* Google, Microsoft / Azure, or Apple sign-in when the company requires SSO
* application tokens for interactive sign-in
* personal account registration after an SSO invitation

**Go to:**

* [How to Sign In to DocStudio](/user/authorization-and-security/how-to-sign-in-to-docstudio.md)
* [How to Set Up SSO Provider](/admin-panel/account-settings/how-to-set-up-sso-provider.md)
* [How to Configure Session Policy](/admin-panel/account-settings/how-to-configure-session-policy.md)

#### Configure Azure SSO for a company

**Goal:** Connect DocStudio to Azure-based company identity management.

**Use:**

* Azure SSO SAML 2.0
* Azure SSO OAuth 2.0
* SSO provider configuration

**Do not use:**

* Microsoft / Azure sign-in when the task is company SSO setup
* personal user sign-in guidance for admin setup
* application tokens for user authentication

**Go to:**

* [How to set up SSO SAML 2.0 with Azure](/admin-panel/account-settings/how-to-set-up-sso-saml-2.0-with-azure.md)
* [How to set up SSO OAuth 2.0 with Azure](/admin-panel/account-settings/how-to-set-up-sso-oauth-2.0-with-azure.md)
* [How to Set Up SSO Provider](/admin-panel/account-settings/how-to-set-up-sso-provider.md)

#### Configure Google SSO for a company

**Goal:** Connect DocStudio to Google-based company identity management.

**Use:**

* Google SSO setup
* SSO provider configuration

**Do not use:**

* Google sign-in when the task is company SSO setup
* email and password when company policy requires SSO
* application tokens for user sign-in

**Go to:**

* [How to Set Up SSO with Google](/admin-panel/account-settings/how-to-set-up-sso-with-google.md)
* [How to Set Up SSO Provider](/admin-panel/account-settings/how-to-set-up-sso-provider.md)

#### Require additional verification with MFA

**Goal:** Add an extra verification step to sign-in.

**Use:**

* MFA

**Do not use:**

* MFA as the main sign-in method
* MFA instead of email and password, provider sign-in, or SSO
* application tokens as a replacement for MFA

**Go to:**

* [Personal Settings Page Overview](/user/user-profile/personal-settings-page-overview.md)
* [How to Sign In to DocStudio](/user/authorization-and-security/how-to-sign-in-to-docstudio.md)
* [How to Configure Session Policy](/admin-panel/account-settings/how-to-configure-session-policy.md)

#### Authorize API requests

**Goal:** Authorize API requests without sharing a user password.

**Use:**

* application tokens
* integrations and API access

**Do not use:**

* application tokens for regular interface sign-in
* user password sharing for integrations
* SSO setup as a replacement for API authorization

**Go to:**

* [Application Tokens (API Access)](/user/authorization-and-security/application-tokens-api-access.md)
* [Integrations & API Access](/admin-panel/integrations-and-api-access.md)

### User sign-in methods

#### Email and password

Use email and password when a user signs in with standard DocStudio credentials.

**When to use:** Use this method when the user has a DocStudio account and wants to sign in directly.

**Best for:**

* standard sign-in
* users who do not use a provider sign-in method
* users who do not need company SSO

**Do not use this when:**

* the user signs in with Google, Microsoft / Azure, or Apple
* the company requires SSO
* the task is API access

**Go to:**

* [How to Sign In to DocStudio](/user/authorization-and-security/how-to-sign-in-to-docstudio.md)
* [Password Rules](/user/authorization-and-security/password-rules.md)
* [How to Change Your Password](/user/user-profile/how-to-change-your-password.md)

#### Google sign-in

Use Google sign-in when the user wants to access DocStudio through a Google account.

**When to use:** Use this method when the sign-in page shows the Google button and the user’s DocStudio access is connected to a Google account.

**Best for:**

* users who use Google as their sign-in provider
* users who do not want a separate DocStudio password
* organizations that allow Google-based access

**Do not use this when:**

* the company requires a separate SSO flow
* the user needs Microsoft / Azure, Apple, or email and password
* the task is API access

**Go to:**

* [How to Sign In to DocStudio](/user/authorization-and-security/how-to-sign-in-to-docstudio.md)

#### Microsoft / Azure sign-in

Use Microsoft / Azure sign-in when the user wants to access DocStudio through a Microsoft or Azure account.

**When to use:** Use this method when the sign-in page shows the Microsoft button and the user’s DocStudio access is connected to a Microsoft or Azure account.

**Best for:**

* users who use Microsoft accounts
* users whose company allows Microsoft / Azure sign-in
* users who do not want a separate DocStudio password

**Do not use this when:**

* the company requires a separate SSO flow
* the task is to configure Azure SSO
* the task is API access

**Go to:**

* [How to Sign In to DocStudio](/user/authorization-and-security/how-to-sign-in-to-docstudio.md)

#### Apple sign-in

Use Apple sign-in when the user wants to access DocStudio through Apple ID.

**When to use:** Use this method when the sign-in page shows the Apple button and the user’s DocStudio access is connected to Apple ID.

**Best for:**

* users who use Apple ID as their sign-in provider
* users who access the profile through Apple sign-in

**Do not use this when:**

* the user must access DocStudio through company SSO
* the user selected Hide My Email and DocStudio cannot complete the flow
* the task is API access

**Go to:**

* [How to Sign In to DocStudio](/user/authorization-and-security/how-to-sign-in-to-docstudio.md)

#### SSO

Use SSO when the company requires users to access DocStudio through a corporate identity provider.

**When to use:** Use this method when the user received an SSO invitation or the company requires SSO for access.

**Best for:**

* corporate users
* company-managed access
* centralized authentication
* admin-controlled security policies

**Do not use this when:**

* the user only needs Google, Microsoft / Azure, or Apple sign-in
* the user has only a personal account
* the task is API access through application tokens

**Go to:**

* [How to Sign In to DocStudio](/user/authorization-and-security/how-to-sign-in-to-docstudio.md)
* [How to Set Up SSO Provider](/admin-panel/account-settings/how-to-set-up-sso-provider.md)
* [How to Configure Session Policy](/admin-panel/account-settings/how-to-configure-session-policy.md)

### Company SSO setup

#### Azure SSO setup

Use Azure SSO setup when a company needs to connect DocStudio to Azure-based identity management.

**When to use:** Use Azure SSO setup when an admin or technical team configures company-level SSO.

**Best for:**

* companies that use Azure or Microsoft identity services
* corporate users who must authenticate through company identity rules
* centralized identity management

**Do not use this when:**

* a user only needs Microsoft / Azure sign-in on the sign-in page
* a personal user just needs to sign in
* the task is API access

**Go to:**

* [How to set up SSO SAML 2.0 with Azure](/admin-panel/account-settings/how-to-set-up-sso-saml-2.0-with-azure.md)
* [How to set up SSO OAuth 2.0 with Azure](/admin-panel/account-settings/how-to-set-up-sso-oauth-2.0-with-azure.md)
* [How to Set Up SSO Provider](/admin-panel/account-settings/how-to-set-up-sso-provider.md)

#### Google SSO setup

Use Google SSO setup when a company needs to connect DocStudio to Google-based identity management.

**When to use:** Use Google SSO setup when an admin or technical team configures company-level SSO.

**Best for:**

* companies that use Google Workspace or Google identity services
* corporate users who must authenticate through company identity rules
* centralized identity management

**Do not use this when:**

* a user only needs Google sign-in on the sign-in page
* a personal user just needs to sign in
* the task is API access

**Go to:**

* [How to Set Up SSO with Google](/admin-panel/account-settings/how-to-set-up-sso-with-google.md)
* [How to Set Up SSO Provider](/admin-panel/account-settings/how-to-set-up-sso-provider.md)

### Security settings

#### MFA

Use MFA when sign-in requires an additional verification step.

**When to use:** Use MFA to add extra protection to sign-in.

**Best for:**

* stronger account protection
* corporate accounts with stricter security requirements
* sign-in flows that need an extra check

**Do not use this when:**

* you need to choose the main sign-in method
* you need API access
* you need to configure an SSO provider connection

**Go to:**

* [Personal Settings Page Overview](/user/user-profile/personal-settings-page-overview.md)
* [How to Sign In to DocStudio](/user/authorization-and-security/how-to-sign-in-to-docstudio.md)
* [How to Configure Session Policy](/admin-panel/account-settings/how-to-configure-session-policy.md)

#### Password policy

Use password policy when a company needs to control password requirements.

**When to use:** Use password policy when security rules must define password complexity, expiration, or reuse behavior.

**Best for:**

* corporate accounts
* admin-managed security settings
* organizations with stricter password requirements

**Do not use this when:**

* the issue is SSO provider setup
* the user signs in only through a provider-based flow
* the task is API access

**Go to:**

* [Password Rules](/user/authorization-and-security/password-rules.md)
* [How to Configure Password Policy](/admin-panel/account-settings/how-to-configure-password-policy.md)

### API access

#### Application tokens

Use application tokens when API requests or third-party integrations need authorization.

**When to use:** Use application tokens for API access, not for regular user sign-in.

**Best for:**

* developers
* API requests
* third-party integrations
* automated processes

**Do not use this when:**

* a user needs to sign in to the DocStudio interface
* a company needs SSO setup
* a user forgot their password
* the user needs MFA for interactive sign-in

**Go to:**

* [Application Tokens (API Access)](/user/authorization-and-security/application-tokens-api-access.md)
* [Integrations & API Access](/admin-panel/integrations-and-api-access.md)

### Common mistakes

Avoid these mistakes when you choose an access method:

* Using Google sign-in when the task is Google SSO setup.
* Using Microsoft / Azure sign-in when the task is Azure SSO setup.
* Using application tokens for regular user sign-in.
* Using MFA as the main sign-in method.
* Using email and password when the company requires SSO.
* Using SSO setup instructions when the user only needs to click Google, Microsoft / Azure, or Apple on the sign-in page.
* Using a personal access flow for a corporate user who received an SSO invitation.
* Resetting the password when the real issue is company SSO configuration.
* Configuring SSO when the task only needs API access through an application token.
* Using user passwords in integrations instead of application tokens.

### Quick decision guide

Use these rules to choose faster:

* If the user has a standard DocStudio account, use email and password.
* If the user signs in through Google, use Google sign-in.
* If the user signs in through Microsoft or Azure, use Microsoft / Azure sign-in.
* If the user signs in through Apple ID, use Apple sign-in.
* If the company manages access through a corporate identity provider, use SSO.
* If the company uses Azure for identity management, configure Azure SSO setup.
* If the company uses Google for identity management, configure Google SSO setup.
* If sign-in needs an extra verification step, use MFA.
* If the task is API access, use application tokens.
* If password rules must be stricter, configure password policy.

### Useful links

#### User sign-in

* [How to Sign In to DocStudio](/user/authorization-and-security/how-to-sign-in-to-docstudio.md)
* [Password Rules](/user/authorization-and-security/password-rules.md)
* [How to Change Your Password](/user/user-profile/how-to-change-your-password.md)

#### Company SSO setup

* [How to Set Up SSO Provider](/admin-panel/account-settings/how-to-set-up-sso-provider.md)
* [How to set up SSO SAML 2.0 with Azure](/admin-panel/account-settings/how-to-set-up-sso-saml-2.0-with-azure.md)
* [How to set up SSO OAuth 2.0 with Azure](/admin-panel/account-settings/how-to-set-up-sso-oauth-2.0-with-azure.md)
* [How to Set Up SSO with Google](/admin-panel/account-settings/how-to-set-up-sso-with-google.md)

#### Security settings

* [How to Configure Password Policy](/admin-panel/account-settings/how-to-configure-password-policy.md)
* [How to Configure Session Policy](/admin-panel/account-settings/how-to-configure-session-policy.md)
* [Personal Settings Page Overview](/user/user-profile/personal-settings-page-overview.md)

#### API access

* [Application Tokens (API Access)](/user/authorization-and-security/application-tokens-api-access.md)
* [Integrations & API Access](/admin-panel/integrations-and-api-access.md)
