Security and Privacy

How to get there: Click Settings in the sidebar → Security tab (under Distribution) and Privacy tab (under Organization).

These settings control how users access your portal and how their data is handled.

Login Methods

Choose which login methods are available on your portal:

  • ProductLift login -- the standard email-and-password login built into ProductLift.
  • Social authentication -- allow users to log in with Google, GitHub, or other social providers. Enable each provider individually.

Single Sign-On (SSO)

How to get there: Click Settings in the sidebar → Security tab → scroll to Single Sign-On (SSO).

Let users log in to your portal automatically from your own application. When SSO is configured, users who are already logged in to your app are seamlessly authenticated in ProductLift without a separate login step. See the SSO documentation for implementation details.

Microsoft 365 / Entra ID SSO

How to get there: Click Settings in the sidebar → Security tab → scroll to Microsoft 365 / Entra ID SSO.

Let your team sign in with their existing Microsoft 365 work account. Login is tenant-restricted, so only members of your organization can sign in, and your existing MFA and conditional access policies in Entra ID apply automatically. See the Microsoft 365 / Entra ID SSO setup guide.

User Acceptance

When enabled, new sign-ups are held in a pending state until an admin approves them. You can also auto-approve users based on their email domain (e.g., approve everyone with an @yourcompany.com address).

Email Verification

Require users to verify their email address before they can post or vote. This helps prevent spam and fake accounts.

Private Portal

Make your portal visible only to logged-in users. Visitors who are not signed in will see a login page instead of your boards. This is useful for internal feedback portals or pre-launch communities.

Maintenance Mode

Temporarily block all access to your portal. When enabled, visitors see a maintenance message instead of the portal. Admins can still access the portal normally.

Show a cookie consent banner to comply with GDPR and similar regulations. When enabled, a banner appears asking visitors to accept cookies before any tracking scripts are loaded.

Privacy Statement

Add a link to your privacy statement. This link appears on the registration page and in emails, letting users know how their data is handled.