The Security Dashboard on Payroll classic is a centralised page dedicated to managing user security access, two-factor authentication (2FA), and single sign-on (SSO). These settings used to be under Manage Users. But with the introduction of this feature, admins now have a one-stop area that makes it easy to see user access and configure 2FA and SSO.
Previously, the Security Dashboard was only available to Full Access users. Full Access users can now also grant Restricted Access users access to the Security Dashboard, so that a business's IT team can manage 2FA and SSO setup without needing to be given full access to payroll.
To get to the Security Dashboard:
- Log in to your Payroll classic platform.
- Click the Business menu.
- Click the Payroll Settings submenu.
- Under Business Management, click Security Dashboard.
Helpful Hint
Restricted Access users will only see the Business Management items they've been granted access to in the left-hand navigation. If a user has only been granted the Security Dashboard, that will be the only item shown under Business Management for them.
Granting a Restricted Access user access to the Security Dashboard
If a user only needs to manage security settings — such as an IT team member who isn't responsible for running payroll — you can give them Restricted Access with just the Security Dashboard enabled, rather than granting them Full Access.
- Navigate to Business > Payroll Settings > Manage Users.
- Click the edit (pencil) icon next to the user you want to update.
- Under Access level, select Restricted access.
- Click the Business Settings tab.
- Under Business Management, tick the Security Dashboard checkbox.
- Click Save.
The user will now be able to access the Security Dashboard the next time they log in, without needing Full Access to the business.
This page has four key parts:
User Security Overview
The User Security Overview page shows the following details per employee:
- Email Address.
- User Type.
- Last Login.
- 2FA Status.
- 2FA Methods.
- Passkeys.
- SSO Status.
You can also filter the employees on the list by:
- 2FA Status.
- User Type.
- Passkey Status.
- SSO Status.
For more information on how to use the User Security Overview page: Manage user security audits using enhanced filtering capabilities.
Two Factor Authentication Settings
The Two Factor Authentication Settings page is where you can configure the following:
- 2FA requirement for Manager/Employee level users.
- Two-Factor Challenges - the requirement of a verification code before taking important actions.
- Require a two-factor challenge before lodging a pay event to the ATO.
- Require a two-factor challenge before submitting a super batch.
For more information on how to configure 2FA: Manage two-factor authentication.
Single Sign-On (SSO) Settings
The Single Sign-On (SSO) Settings tab is where you configure your business's SAML SSO connection with your identity provider (e.g. Okta, Azure AD, Google Workspace). To set this up, you'll need the following details from your identity provider:
- SAML Sign-on URL - the URL your identity provider uses to initiate sign-on.
- Issuer - the identifier for your identity provider.
- Entity ID - the unique identifier for this SAML connection.
- Primary x509 Certificate - the certificate provided by your identity provider used to verify SAML responses. Use the eye icon to show or hide the certificate value. If your identity provider issues a secondary or backup certificate, click Add another certificate to include it.
Once you've entered your details, click Test configuration & Save to validate the connection and save your settings, or Cancel to discard your changes.
Helpful Hint
Setting up SSO here only configures the connection between your business and your identity provider. To control which individual users have SSO enabled, use the Single Sign-On (SSO) Access tab.
Single Sign-On (SSO) Access
Once your SSO connection has been configured under Single Sign-On (SSO) Settings, use the Single Sign-On (SSO) Access tab to manage which users are enabled for SSO.
This tab shows a list of users with the following columns:
- Name.
- Email Address.
- SSO Email - the email address used to match the user to their identity provider account. Click the pencil icon next to a user to edit this.
- Status - shows whether SSO is enabled for the user, or if no SSO email has been provided yet.
From this tab, you can:
- Filter the list using the dropdown in the top left (default: All).
- Search for a user by name or email.
- Select one or more users using the checkboxes, then click Enable SSO or Disable SSO to update their access in bulk.
- Export the list of users and their SSO status.
- Import SSO email addresses in bulk.
Helpful Hint
A user's Status will show No email provided until an SSO Email has been added for them. Add or update this using the pencil icon before enabling SSO for that user.
Once you have completed the above steps, your business's user security, 2FA, and SSO settings will be fully configured and ready to use.