Domain Verification¶
BongoShield routes and isolates users by their email domain. Getting your domains right is what makes sure every employee lands in your organization — and only yours — and that sign-in sends each person down the correct path (SSO, LDAP, or local password).
This page explains what "domain" means across BongoShield, what you control yourself, and what is handled during onboarding.
Why domains matter¶
- Correct user routing. When someone enters their email, BongoShield reads the domain to decide how they sign in — redirect to your IdP if the domain is federated (SSO), the AD/LDAP path if it matches a directory, or the local password form otherwise.
- Tenant trust and isolation. In cloud/pooled BongoShield, many organizations share one platform. Tying your domains to your tenant is what keeps a stranger on a public address from being routed into your organization, and keeps your users' data separate from every other customer's.
What you control yourself¶
You set allowed email domains directly on each identity source — no ticket required:
- SSO providers — every provider in Settings → Single sign-on has an
Allowed email domains field. Users on those domains are sent to that provider.
Public/consumer domains (
gmail.com,outlook.com, …) are rejected — you can only add domains your organization owns. See SSO. - LDAP / AD directories — each domain you add in Settings → LDAP / AD declares the directory's domain, which is used to route matching users to that directory. See LDAP / Active Directory.
Adding, editing and removing these domains is entirely self-service and takes effect immediately.
What is handled during onboarding¶
Provisioning your organization and activating your tenant's verified domains is done by BongoShield during onboarding today — it is operator-assisted, not a self-serve button in the admin console. This is deliberate: in pooled cloud BongoShield, proving that a tenant genuinely owns a domain (before it can claim and route that domain) is a trust boundary, and public self-signup with automated domain-ownership verification is still on the roadmap rather than shipped.
Practically, this means:
- Your organization and its domain(s) are established when your tenant is set up.
- From then on you self-serve the day-to-day domain configuration: which domains each SSO provider or directory covers, in the settings above.
- If you acquire a new domain the organization owns and need it recognized at the tenant level, contact BongoShield to have it added to your tenant; you then attach it to the relevant SSO/LDAP source yourself.
There is no self-serve 'verify a domain' button in the admin console
Admins configure allowed email domains on their SSO/LDAP providers. Tenant-level domain verification/activation is performed by BongoShield during onboarding. If you're expecting a DNS-TXT "verify your domain" flow inside Settings, that isn't part of the admin console today.