Skip to main content
UI Coach Logo
Advanced

SSO Domain Verification

Design an enterprise setup flow for proving domain control before enforcing single sign-on for matching users.

Desktop web4 hours plus

The brief

Understand the problem

Background

An organization may use domain ownership to claim users or enforce an identity provider. DNS changes can be delayed, delegated domains can overlap, and premature enforcement can lock out administrators.

User context

Identity administrator Laila is connecting example.co to the company identity provider. A subsidiary already uses eu.example.co, and two emergency administrators must keep an alternate sign-in route.

Product problem

Verification and enforcement need separate, comprehensible stages with ownership conflict resolution and tested recovery access.

Objective

Create domain entry, DNS proof, ownership conflict handling, and safe enforcement review for enterprise sign-on.

What to design

Define the experience

Required experience

  • Enter a domain and inspect affected users
  • Publish and verify a DNS record
  • Resolve an existing domain claim
  • Test sign-in and enable enforcement with recovery controls

Screens and states

  • Domain setup
  • DNS verification
  • Ownership conflict
  • Enforcement review

Core user flow

Follow the critical path

  1. 01

    Laila enters example.co and reviews user and subdomain impact

  2. 02

    She publishes the generated DNS record and waits for propagation

  3. 03

    The service identifies the subsidiary claim and preserves its boundary

  4. 04

    She tests identity-provider sign-in and verifies two recovery administrators before enforcement

Product rules

Requirements and constraints

Requirements

  • Use a unique verification value with copy and validation guidance
  • Show DNS lookup evidence and propagation status
  • Explain parent-domain and subdomain ownership relationships
  • Require a successful test and recovery-admin confirmation before enforcement

Constraints

  • Verification cannot expose secret identity-provider credentials
  • Domain proof does not by itself authorize user takeover
  • At least one tested recovery route must remain

Reality check

States worth considering

DNS records are proxied or cached
Another tenant claims the domain
The identity provider is unavailable
An administrator closes the final recovery route

Finish line

What to deliver

  • Four desktop screens showing verification, conflict, and enforcement safety

Optional direction

Visual resources

Use these as a starting constraint if you want one. They are not part of the required solution.

Font pairing
Cormorant GaramondProza Libre

Cormorant Garamond & Proza Libre

Clear interface writing gives people the confidence to understand what changed and decide what to do next.

Icons
Illustrations

Keep practicing

Advanced
Security

Share a Confidential File With Expiring Access

Design a secure file-sharing flow with recipient verification, access limits, activity history, and revocation.

Desktop web4 hours plus
Trust and SafetyInformation Architecture
Advanced
Security

Audit Log Investigation

Design an investigation workspace that helps a security analyst trace a suspicious administrative change across actors and systems.

Desktop web4 hours plus
Search and FilteringData Visualization
Advanced
Security

Respond to a Home Monitoring Alert

Design a home dashboard that prioritizes unusual sensor events, communicates device health, and supports safe remote action.

Tablet4 hours plus
Dashboard DesignTrust and Safety
Advanced
Security

Review a Security Camera Event

Design an event-review flow that helps a resident verify what happened, preserve relevant evidence, and avoid unnecessary sharing.

Mobile2 to 4 hours
Trust and SafetyInteraction Design
Advanced
Security

Time-Bound Secret Access

Design a request and approval flow for temporary production-secret access with purpose, scope, and automatic expiry.

Desktop web4 hours plus
Trust and SafetyInteraction Design
Advanced
Security

Verified Caller Identity Card

Design an incoming-call experience that shows identity information the caller has explicitly verified and shared, without covert imaging or detection.

Mobile4 hours plus
Trust and SafetyInformation Hierarchy