Skip to main content

Understanding Hyperproof email verification

Learn how email verification requirements work in Hyperproof based on your identity provider.

Overview

When signing in or accepting invitations to Hyperproof, email verification requirements depend directly on your authentication method. Hyperproof treats certain identity providers as trusted, enabling a seamless experience, while requiring an additional layer of email verification for less-trusted or password-based sign-in methods.

Key benefits / use cases

  • Streamlined access: Learn which authentication providers allow users to skip extra verification steps.

  • Enhanced security: Understand why email verification is required for email and password setups and Office 365.

  • One-time completion: Know when email verification only needs to be completed once to permanently gain access.

How Hyperproof email verification works

Different identity providers (IdPs) and sign-in methods follow specific verification rules when users access Hyperproof:

Authentication Method

Identity Provider Trust Status

Verification Required?

Verification Details

Google

Trusted

No

Users never need to complete email verification when accepting invitations or signing in.

Single Sign-On (SSO)

Trusted

No

Users never see email verification requirements, regardless of the configured IdP (Okta, Azure AD/SAML, ADFS, etc.).

Office 365 (O365)

Not trusted

Yes

Users must verify their email once upon accepting an invitation or on a subsequent sign-in attempt.

Email + Password

Standard signup flow

Yes

Verification is part of Auth0's signup and invitation flow. Users are blocked until verification is completed.

Email verification by provider type

Trusted identity providers (Google & SSO)

Hyperproof treats Google as a trusted identity provider. Users accepting invitations or signing in with Google do not need to go through email verification.

Similarly, Single Sign-On (SSO) is treated as a trusted identity provider regardless of which IdP your organization configures, such as Okta, Entra, or JumpCloud. Users accepting invitations or signing in with SSO never see the email verification requirement.

Office 365 (O365)

Hyperproof treats the O365 authentication provider as not trusted. Because of this, O365 users must complete an extra step to verify their email.

Users can verify their email either when accepting their invitation or during a subsequent login if they did not complete the verification step at the time of acceptance.

Note O365 users only have to verify their email address once. Hyperproof stores the verification status in the user's database record, so users never see the verify email prompt again.

Email and password sign-in

For users signing into Hyperproof with an email and password, email verification is handled through Auth0's standard signup and invitation flow.

Email and password users who accept an invitation but don't complete email verification are locked out of Hyperproof until they complete verification. This restriction applies to the invitation acceptance moment and on subsequent sign-in attempt until verification is completed.

Once an email and password user verifies their email address, they won't encounter the verification requirement on subsequent sign-ins.

Troubleshooting

Users locked out while accepting an invitation

If an email and password user accepts an invitation but fails to complete the email verification step, Hyperproof will not allow them to sign in.

To gain access to Hyperproof, the user must check their inbox or spam folder for the verification email and complete the verification process. Once verified, the sign-in prompt will no longer block them on subsequent sign-in attempts.

O365 users seeing repeated sign-in prompts

If an O365 user skipped or bailed out of the email verification prompt while accepting their initial invitation, Hyperproof will prompt them again on their next sign-in attempt.

To permanently dismiss the prompt, the O365 user must complete the email verification process. Once completed, Hyperproof saves the verified status to their user database record, and the prompt won't appear again.

Did this answer your question?