Skip to main content
UI Coach Logo
Back to challenges
Hard

SSO Domain Verification

Design an enterprise setup flow for proving domain control before enforcing single sign-on for matching users.

Desktop web

The brief

Understand the problem

Background

An organization may use domain ownership to claim users or enforce an identity provider. DNS changes can be delayed, delegated domains can overlap, and premature enforcement can lock out administrators.

User context

Identity administrator Laila is connecting example.co to the company identity provider. A subsidiary already uses eu.example.co, and two emergency administrators must keep an alternate sign-in route.

Product problem

Verification and enforcement need separate, comprehensible stages with ownership conflict resolution and tested recovery access.

Objective

Create domain entry, DNS proof, ownership conflict handling, and safe enforcement review for enterprise sign-on.

What to design

Define the experience

Required experience

  • Enter a domain and inspect affected users
  • Publish and verify a DNS record
  • Resolve an existing domain claim
  • Test sign-in and enable enforcement with recovery controls

Screens and states

  • Domain setup
  • DNS verification
  • Ownership conflict
  • Enforcement review

Core user flow

Follow the critical path

  1. 01

    Laila enters example.co and reviews user and subdomain impact

  2. 02

    She publishes the generated DNS record and waits for propagation

  3. 03

    The service identifies the subsidiary claim and preserves its boundary

  4. 04

    She tests identity-provider sign-in and verifies two recovery administrators before enforcement

Product rules

Requirements and constraints

Requirements

  • Use a unique verification value with copy and validation guidance
  • Show DNS lookup evidence and propagation status
  • Explain parent-domain and subdomain ownership relationships
  • Require a successful test and recovery-admin confirmation before enforcement

Constraints

  • Verification cannot expose secret identity-provider credentials
  • Domain proof does not by itself authorize user takeover
  • At least one tested recovery route must remain

Reality check

States worth considering

DNS records are proxied or cached
Another tenant claims the domain
The identity provider is unavailable
An administrator closes the final recovery route

Finish line

What to deliver

  • Four desktop screens showing verification, conflict, and enforcement safety

Optional direction

Visual resources

Use these as a starting constraint if you want one. They are not part of the required solution.

Color palette
#1C1B19
#C7B89F
#649853
#735D5F
#87759D
Font pairing
Cormorant GaramondProza Libre

Cormorant Garamond & Proza Libre

Clear interface writing gives people the confidence to understand what changed and decide what to do next.

Icons
Illustrations