Commit Graph
24 Commits
Author SHA1 Message Date
Eduard GertandClaude Opus 5 4df2518616 Add Sign-in Domains page (#970)
* Add Sign-in Domains page

Documents how an email domain is matched to an account: adding a domain,
proving ownership with a DNS TXT record, and what changes for users once it is
verified.

Two points the page is careful about, because both are easy to assume wrongly:

- Verifying a domain decides where *new* users land. It does not move users who
  already have an account of their own, so domains want adding before a team is
  onboarded rather than after.
- A verified sign-in domain is not an SSO domain. Routing a domain to an
  identity provider is a separate step on the integration, which is what lets
  one domain sign in through SSO while another uses Google or a social login.

The four screenshots it references are not in this commit and need to be added
before merge:

  public/docs-static/img/manage/team/sign-in-domains/
    sign-in-domains-settings.png          the Sign-in Domains tab in Settings
    sign-in-domains-pending.png           a newly added domain, Pending
    sign-in-domains-dns-verification.png  the TXT record dialog
    sign-in-domains-login.png             the login page

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Tighten the Sign-in Domains page

Switches the examples to company.com / company.net, drops the step-by-step
walkthrough of how matching works, and trims the instructions down to what a
reader actually needs to do. The prose and the callouts carry the page now.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Trim the Sign-in Domains page further

Parallel section titles (Add / Verify / Remove Domain), drops the
"What Changes for Your Users" and "Things Worth Knowing" sections, and cuts
the availability note and the SSO note back to one line each.

The warning now says to add domains before onboarding a team from another
domain, which is the case it actually matters for.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Move Sign-in Domains under Settings, and lead with the two domains

Sign-in Domains is a Settings tab in the dashboard, not part of Team, so the
page moves to /manage/settings/sign-in-domains and sits in the Settings nav
after Authentication, mirroring the dashboard's own tab order. Screenshots move
with it to img/manage/settings/sign-in-domains/.

The intro also led with jane@company.com, which would already have matched the
primary domain and so did not show the problem at all. It now establishes
company.com as the account's own domain and company.net as the second one, and
the colleague who needs it is jane@company.net.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Lead with what sign-in domains are for

Retitles the page "Allow Users from Other Domains to Join Your Account", which
is the job it does, and opens with the behaviour rather than with the account's
own domain: users on one business email domain are already joined into one
account, and most businesses have more than one domain -- another location, a
country domain, a second brand -- whose users are not.

Also documents the email route the verification dialog offers for anyone
without DNS access, and matches the dialog's own wording (Verify on the row,
then Start Verification).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Sharpen the intro and drop the primary-domain aside

- The colleague on another domain is not recognized unless invited by hand, so
  the intro says so and links to the invite page.
- "With sign-in domains you prove ownership of those domains, and everyone
  across your organization joins the same account."
- Drops the paragraph about company.com staying the primary domain. Remove
  Domain named that term without defining it afterwards, so it now says "the
  domain your account signed up with" instead.
- Drops the detail about the retry interval widening; that it keeps checking is
  the part a reader needs.
- US spelling, matching the rest of the docs.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Shorten the one-account-per-domain note

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Drop the SSO section, and nest the page under Authentication

The "Sign-in Domains and SSO" section read as confusing rather than
clarifying, so it goes along with its recap bullet. The constraint a reader
actually meets survives in Remove Domain: a domain an SSO integration uses
cannot be deleted until it is detached there.

The page also moves under the Authentication group in the sidebar, next to
Peer Session Expiration and Multi-Factor Authentication.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Follow the dashboard: Sign-in Domains lives under Authentication

The dashboard no longer gives sign-in domains a tab of their own, so the
instruction now sends the reader to Settings > Authentication and the section
within it. The screenshot is renamed to authentication-tab.png to match what
it has to show.

Also spells out that joining happens automatically without direct invites,
and drops the same point from the opening paragraph where it was now said
twice.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Move the page under Single Sign-On

/manage/team/single-sign-on/sign-in-domains, nested under Single Sign-On in
the Team section rather than sitting under Settings. Screenshots move with it
to img/manage/team/single-sign-on/sign-in-domains/.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Put the page at manage/team/sign-in-domains

A sibling of Single Sign-On in the Team section, listed after it, rather than
nested inside it or under Settings. Screenshots follow to
img/manage/team/sign-in-domains/.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Fix wording and a stale example domain

The DNS instruction still named www.company.net after the example moved to
company.co.uk, which is the one that actually misleads: that sentence is
telling people where to put the record.

Also a "usees" typo, a link with no object ("unless you invite manually"), a
missing comma after "By default", "as you" where the comparison is to your
domain, "E.g." opening a sentence, and "another one" where it means another
account.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Drop the authentication clause from the recap

It summarised the SSO section, which is gone.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Add the Sign-in Domains screenshots

- authentication-tab.png: the section under Authentication, with two domains
  pending and two verified, which is what the page describes
- dns-verification.png: the Verify Domain Ownership dialog
- login.png: the login page

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Point domain verification help at NetBird Support

Replace the support@netbird.io mailto links with links to the support
page, and tell users with an account they were not aware of to reach out
so the team can verify their identity and point them to its admin.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-28 10:19:37 +02:00
Brandon Hopkins 0d44d0b7ba Trim Okta, Keycloak, JumpCloud, and IIJ ID sync screenshots (#982) 2026-09-24 15:24:55 -07:00
Brandon Hopkins 75080c9e32 Trim Microsoft Entra ID IdP sync screenshots (#981) 2026-09-24 15:19:31 -07:00
Brandon HopkinsandJack Carter cbffc4abea Trim Google Workspace IdP sync screenshots (#980)
* Trim Google Workspace IdP sync screenshots

* docs: render the GCP permissions callout as a Note

* docs: scope the GCP key-creation exception to the NetBird project

Replace the org-wide deletion of iam.disableServiceAccountKeyCreation
with a project-level override, and restore enforcement after the key
is uploaded.

---------

Co-authored-by: Jack Carter <128555021+SunsetDrifter@users.noreply.github.com>
2026-09-24 15:12:04 -07:00
Brandon Hopkins 6641cd73b4 Trim SSO walkthrough screenshots and fix alt text (#983) 2026-09-24 15:11:10 -07:00
Bethuel Mmbaga f5dacdd2fb Add IIJ ID SSO and SCIM provisioning guides (#922) 2026-08-14 19:21:58 +03:00
Bethuel Mmbaga fd04046f5f Update Entra ID SCIM docs for the new Azure portal UI (#909) 2026-08-10 12:25:39 +03:00
Brandon Hopkins b70301ee4d Image Audit: Unreferenced Images (#787) 2026-06-11 19:22:11 -07:00
Jack Carter 6a31154b96 Add dedicated User Roles page (#789)
Create a standalone User Roles reference covering all six roles (Owner,
Admin, Network Admin, Billing Admin, Auditor, User) with a permission
matrix aligned to the current dashboard, per-role sections, API/token
notes, and role-assignment steps.

Reduce the role section on the Add Users page to a pointer (keeping the
existing anchor), repoint inbound links from delete-account,
control-center, and msp-portal, add the page to the Team sidebar, and
refresh the role screenshots.
2026-06-11 16:19:08 +02:00
Brandon HopkinsandPizzaLovingNerd 39303d1c48 Align docs with the new dashboard UI (Phase 1) (#778)
* bulk text edit to fit new flows

* Updated screenshots, some minor docs fix. (#782)

* Update Settings on site-to-site.mdx

* fix image names and embedded links

* Update high level dia

* general dashboard images and auto-update stucture fix

* remove temp audit file

---------

Co-authored-by: PizzaLovingNerd <cameron@stillhq.io>
2026-06-10 09:24:36 -07:00
Bruno Mercier Costa 6107943b50 Update Entra Provisioning Screenshot (#785) 2026-06-10 09:59:16 +02:00
Bethuel Mmbaga a8c86c48e0 Add Zoho Directory SSO (#780) 2026-06-08 18:12:40 +03:00
Bruno Mercier Costa 58f1e94ec4 SSO Screenshot Update (#732)
SSO Screenshot Update
2026-05-07 16:15:23 +02:00
Bethuel Mmbaga d36c932b86 Add AWS Cognito SSO (#717) 2026-04-30 11:05:40 +03:00
Bethuel MmbagaandJack Carter e0076457c8 Add IdP sync docs for embedded IdP (#696)
* Add embedded IdP sync docs

* Link idp sync to embedded idp sync docs

* fix: Add missing Note imports and fix NerBird typo in idp-sync docs

---------

Co-authored-by: Jack Carter <128555021+SunsetDrifter@users.noreply.github.com>
2026-04-21 14:23:55 +02:00
Bethuel Mmbaga a95036e9ee Add Zitadel SSO docs (#691) 2026-04-09 17:19:26 +03:00
Jack Carter 679ad7b3ad docs: add Entra ID enterprise application enablement guide (#677)
Add documentation for enabling the NetBird enterprise application in
Microsoft Entra ID, including finding the app by Application ID and
granting admin consent for the directory.
2026-04-01 16:37:56 +02:00
Bethuel Mmbaga 31a1eb5642 Update keycloak initial sync steps (#654) 2026-03-16 14:28:45 +03:00
Bethuel Mmbaga cb44c913b7 Update Microsoft Entra SCIM docs (#642) 2026-03-03 20:44:41 +03:00
Bethuel Mmbaga 3c8736f8f6 Add cidaas idp sso (#641) 2026-02-27 11:57:21 +03:00
Bethuel Mmbaga a2f787134f Add duo security idp sso (#511) 2025-12-12 18:53:43 +03:00
Brandon Hopkins e45bb7ce11 Final Doc Restructure (#497) 2025-11-27 09:50:03 -08:00
Bethuel Mmbaga 969fd8afaf Add Entra ID SCIM (#468) 2025-11-25 11:35:48 +03:00
Brandon Hopkins 0080ae97df Restructuring Phase 3 (#492) 2025-11-24 18:25:44 +01:00