Organisation administration · Public
Custom domains for enterprise sign-in
Serve branded enterprise sign-in and the workforce portal on your own hostname.
Enterprise tenants can publish workforce sign-in and the workforce portal on a single custom hostname, such as workforce.example.com. The vanity URL on Skyfallen ({subdomain}.skyfallen.one) redirects to that hostname when the feature is enabled.
Configure the hostname under IAM → Organisation → Profile → Custom domain. You need the domains:manage permission.
| Requirement | Why |
|---|---|
| Enterprise tenant with Workforce Identity | Custom domains are available only on workforce enterprise tenants. |
| Verified organisation domain | The hostname must belong to a domain you already verified under Domains. |
| Vanity subdomain | Your existing vanity slug and lookup-by-email must already be configured. They stay in use for redirects and internal routing. |
| Hostname DNS + SSL | ONE provisions the hostname and edge certificate. Complete ownership verification, point the hostname CNAME at the target ONE shows, then wait for SSL to become active. |
Set up the hostname
IAM walks you through four steps. The wizard resumes where you left off when you return.
When the hostname sits under a domain you already verified — for example workforce.example.com when example.com is verified — ONE can skip the TXT step and move straight to SSL provisioning.
| Step | What you do |
|---|---|
| Hostname | Enter the hostname, review the warnings, and confirm that passkeys on the previous hostname will be disabled when you change it. |
| Verify DNS | Add the TXT record ONE shows for the hostname, then choose Mark DNS verified when the record is live. |
| Provision SSL | Point the hostname at the CNAME target ONE shows, start or refresh SSL provisioning, and wait until the status is Active. |
| Enable | Turn on the custom domain when the hostname is ready. Confirm the passkey impact before saving. |
After setup is complete
When the custom domain is enabled and SSL is active, the panel shows a status summary with the hostname, DNS verification state, and SSL status. Use Reset and start over if you need to remove the hostname entirely and configure a different one.
Resetting removes the hostname from ONE, disables the custom domain, tears down edge SSL provisioning, and disables passkeys registered on that hostname. You must confirm the passkey impact before ONE proceeds.
Passkeys and enforcement
Passkeys are bound to the hostname where they were registered. Custom domain changes affect which passkeys stay active.
Members do not see disabled passkeys in My → Security. IAM administrators can review disabled credentials — including the hostname and reason — on a member record.
If passkey enforcement applies to a member and they no longer have an active passkey, they must register a new one on the current sign-in hostname before they can continue. When a custom domain is enabled, enforced enrollment and new passkey registration from My → Security run on that hostname.
| Action | Passkey impact |
|---|---|
| Enable the custom domain | Active passkeys registered on other hostnames — including auth.skyfallen.one — are disabled for tenant members. Members need a passkey on the custom hostname to sign in with one. |
| Change the hostname | Passkeys registered on the previous hostname are disabled. The custom domain is turned off until you complete setup and enable it again. |
| Disable the custom domain | Passkeys registered on that hostname are disabled. Sign-in returns to the platform hostnames. |
| Reset and start over | Passkeys registered on the removed hostname are disabled. |
Vanity URL and bookmarks
When the custom domain is enabled, {subdomain}.skyfallen.one redirects to your custom hostname. Update bookmarks, email links, and integration redirect URIs that still point at the vanity URL.
| Surface | Location |
|---|---|
| IAM administration | iam.skyfallen.one |
| My account and security | my.skyfallen.one (reachable from the custom portal through a silent account handoff) |
| SAML Entity ID / metadata | https://auth.skyfallen.one/saml/metadata — SP configuration does not move |
| CAS token exchange | idms.skyfallen.one |
Email discovery
When custom domain is enabled, people who enter an @yourdomain.com address on the central sign-in page are forwarded to your custom hostname instead of signing in on auth.skyfallen.one.
Password reset, passkey sign-in, passkey enrollment, and consent use the same flows on the custom hostname once it is enabled.
SAML and CAS
Sign-in and consent can complete on your custom hostname. SAML assertions still use the platform Entity ID. CAS applications may use your custom hostname for the authorise step; the server-side code exchange remains on IDMS.
Related guides
- Manage enterprise domains — email namespace verification
- Brand your sign-in and portal — copy and assets shown on the custom hostname
- Your account and security — registering passkeys on the current hostname