---
title: "Control Restrict UI Feature"
slug: "control-restrict-ui-feature"
updated: 2026-02-24T20:25:56Z
published: 2026-02-24T20:25:56Z
---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.workspot.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Control Restrict UI Feature

**Prerequisites**

- Azure AD(Entra ID) or SAML are enabled, and customers can log in to Control with Entra ID/SAML.
- Create or select a “Designated Administrator” Control Admin account. This account can bypass the Entra ID or SAML account in case of trouble with your identity provider.

**Procedure**

![](https://cdn.us.document360.io/ad9153e1-c8de-4f56-94f2-b717a1fc3a68/Images/Documentation/d64493c7-8104-4094-89e0-08f4d7f4b334.png)

- Sign into Workspot Control
- Go to “Setup > Configuration > Authentication and Registration.”
- At the bottom of the “Authentication and Registration” section, set “Control Authentication” to “Azure AD (Entra ID)” or “SAML.”
- If you don’t see “Control Authentication,” contact Workspot to have the feature enabled.

![](https://cdn.us.document360.io/ad9153e1-c8de-4f56-94f2-b717a1fc3a68/Images/Documentation/888349a7-ce0e-4b3d-8d14-8a67a16459b0.png)

- Go to “Setup > Configuration > Access > Control Access.”
- If you don’t see “Control Access,” contact Workspot to have the feature enabled.
- Check the option “Require Third-party Authentication (Azure AD or SAML) for Control logins”.
- On the “Designate a Named Administrator” menu, select a Control Administrator. This account will be able to bypass the third-party IdP in case of an IdP failure, so this account should have an especially secure password. Creating an account specifically for the purpose is a good idea.
- Click “Save” and you will be prompted with a confirmation message that explains what will change:

![](https://cdn.us.document360.io/ad9153e1-c8de-4f56-94f2-b717a1fc3a68/Images/Documentation/image-1771964655210.png)

**Verification**

- Login with designated administrator from Control GUI on your Local Sign-in URL: [https://control.workspot.com/login/local/*companyIdentifier*](https://control.workspot.com/login/local/companyIdentifier). This should work.
- Using the same URL, try to sign in as another Control user. This should fail.
- Logins using your IdP via [https://control.workspot.com/](https://control.workspot.com/login/local/companyIdentifier)[*companyIdentifier*](https://control.workspot.com/companyIdentifier) should work.
