Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
16 commits
Select commit Hold shift + click to select a range
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
49 changes: 35 additions & 14 deletions docs/articles/new-expensify/domains/Claim-and-Verify-a-Domain.md
Original file line number Diff line number Diff line change
@@ -1,11 +1,10 @@
---
title: Claim and Verify a Domain
description: Learn how to claim and verify a private domain in New Expensify to enable SAML login and unlock enhanced security features.
keywords: [New Expensify, claim domain, verify domain, private domain, domain settings, enhanced security, SAML, domain admin]
internalScope: Audience is Domain Admins and IT admins. Covers claiming a domain and verifying domain ownership via DNS. Does not cover SAML configuration details, Domain Members management, Domain Groups, or login troubleshooting.
keywords: [New Expensify, claim domain, verify domain, private domain, domain settings, enhanced security, SAML, domain admin, domain verification, DNS TXT record, verify domain for SAML, how to verify domain, SAML setup]
---

<div id="new-expensify" markdown="1">

If you have a private domain (e.g., yourcompany.com), you can claim and verify it in Expensify to manage employee permissions and enable additional security features.

# What you can do with a claimed and verified domain
Expand All @@ -14,21 +13,19 @@ Once you've claimed and verified a domain, you can:
- Configure SAML login
- Enforce SAML login for domain members

# Step 1: Claim Your Domain
## How to claim a domain in Expensify

To claim a private domain, you must:
- Be logged in with an email address from that domain
- Have verified your contact method with a magic code

## Steps to claim your domain
1. From the left-hand menu, go to **Workspaces > Domains**.
2. Click the Enable button.
a. If you have already claimed one or more domains, click the **New** button in the upper-right hand corner > **New domain** to add a new domain.
2. Click the **Enable** button.
- If you have already claimed one or more domains, click the **New** button in the upper-right hand corner > **New domain** to add a new domain.
3. Enter the name of your private domain (e.g., `yourcompany.com`) in the form.
4. Click **Continue**.


# Where to find domain settings
## Where to find Domain settings

From the left-hand menu, select **Workspaces > Domains**.

Expand All @@ -39,19 +36,17 @@ Each domain is listed in its own row, showing:
- Verification status (Verified, Not verified)
- Overflow menu with management options


## What happens next?
## What happens after claiming a domain?

Depending on your email setup:

- **If you're not using an email from that domain**: You'll see an error. You can't claim domains that don't match your email address..
- **If you're not using an email from that domain**: You'll see an error. You can't claim domains that don't match your email address.
- **If your email is from that domain but not verified**: You’ll be prompted to verify your login using a magic code.
- **If the domain is already claimed**: You’ll need to coordinate with an existing admin to request that your role be updated to Domain Admin.

After the domain is successfully claimed, the domain will appear under **Workspaces > Domains** in the **Not verified** state.


# Step 2: Verify Your Domain
## How to verify a domain

To unlock advanced security settings and enable SAML, the domain must be verified through a DNS record.

Expand All @@ -64,3 +59,29 @@ To unlock advanced security settings and enable SAML, the domain must be verifie
4. Save your changes.

Once verified, you’ll see a confirmation message and your domain will be marked as **Verified**.

---

# FAQ

## Do I need to verify my domain to use SAML?

Yes. Verifying the domain is required to enable and enforce SAML login. Without verification, the SAML configuration option will remain locked.

## Can I verify multiple domains?

Yes, you can claim and verify multiple domains if your organization operates under more than one. Each must be verified through its own DNS record.

## Can I skip domain verification and still use Expensify?

Yes, you can use Expensify without claiming a domain. However, domain control is required to enable SAML login and enforce centralized security policies.

## I added the TXT record but verification is still failing — what now?

Make sure:
- The record is live and publicly visible (use a DNS checker tool to confirm)
- You’ve added only one TXT record, and it matches the value from Expensify exactly
- You saved the changes and waited for DNS to propagate

If you're still stuck, reach out to your IT team or DNS host for help.

55 changes: 55 additions & 0 deletions docs/articles/new-expensify/domains/Domain-Admins.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
---
title: Domain Admins
description: Learn how to add and manage Domain Admins in New Expensify.
internalScope: Audience is Domain Admins. Covers adding and removing Domain Admins and what Domain Admins can manage. Does not cover Domain Members, Domain Groups, SAML setup, or login troubleshooting.
keywords: [New Expensify, domain admins, domain control, domain settings, domain management]
---

Domain Admins manage your company’s domain settings in Expensify. They can claim domains, verify domain ownership, manage domain members, and configure domain-level security settings (like [SAML SSO](https://help.expensify.com/new-expensify/hubs/domains/)).

---

## How to add a Domain Admin

**To add a Domain Admin:**
1. Go to **Workspaces > Domains**.
2. Select your domain.
3. Open **Domain Admins**.
4. Enter the admin’s email address or phone number, then click **Add**.

**Note:** A Domain Admin does not need an email address on the company domain. For example, an external bookkeeper can be a Domain Admin.

---

## How to remove a Domain Admin

**To remove a Domain Admin:**
1. Go to **Workspaces > Domains**.
2. Select your domain.
3. Open **Domain Admins**.
4. Select the admin, then click **Remove**.

Comment thread
twisterdotcom marked this conversation as resolved.
---

# FAQ

## Do I need to verify my domain to add Domain Admins?

No. You can add Domain Admins after you claim the domain. Verification is required to enable advanced features like SAML and to manage domain members.
Comment thread
twisterdotcom marked this conversation as resolved.

## Can I have multiple Domain Admins?

Yes. There’s no limit to the number of Domain Admins you can assign. We recommend giving access to multiple people in case someone becomes unavailable.

## Can I add a Domain Admin who doesn’t have a company email?

Yes. Domain Admins do not need to use your company’s email domain. You can add personal emails, contractors, or partners as Domain Admins if needed.

## How do I revoke Domain Admin access?

Go to **Workspaces > Domains**, open your domain, and select **Domain Admins**. From there, click **Remove** next to the person you want to revoke access for.

## Who can be a Domain Admin

You can add any Expensify user as a Domain Admin, regardless of whether they use your private domain or a public domain like gmail.com.

1 change: 1 addition & 0 deletions docs/redirects.csv
Original file line number Diff line number Diff line change
Expand Up @@ -893,6 +893,7 @@ https://help.expensify.com/articles/new-expensify/expensify-card/Enable-Expensif
https://help.expensify.com/articles/expensify-classic/bank-accounts-and-payments/bank-accounts.md/Add-or-remove-a-business-bank-account,https://help.expensify.com/articles/expensify-classic/bank-accounts-and-payments/bank-accounts/Connect-US-Business-Bank-Account
https://help.expensify.com/articles/Unlisted/Compliance-Documentation.md,https://help.expensify.com/articles/new-expensify/settings/Encryption-and-Data-Security
https://help.expensify.com/articles/new-expensify/workspaces/Verify-a-Domain,https://help.expensify.com/articles/new-expensify/domains/Claim-and-Verify-a-Domain
https://help.expensify.com/articles/new-expensify/workspaces/Claim-and-Verify-a-Domain,https://help.expensify.com/articles/new-expensify/domains/Claim-and-Verify-a-Domain
https://help.expensify.com/articles/new-expensify/workspaces/Set-Up-SAML-Single-Sign-On,https://help.expensify.com/articles/new-expensify/domains/Set-Up-SAML-SSO
https://community.expensify.com/discussion/4751/how-to-add-an-ach-business-bank-account-to-reimburse-employees-us-only,https://help.expensify.com/articles/expensify-classic/bank-accounts-and-payments/bank-accounts/Connect-US-Business-Bank-Account
https://community.expensify.com/discussion/5700/deep-dive-approval-workflow-overview/,https://help.expensify.com/articles/expensify-classic/reports/Create-a-report-approval-workflow
Expand Down
Loading