Available for: Enterprise Plan
Set up by: Company Admin
Data security and confidentiality are the main concerns for most enterprises. That's why our Enterprise Plan provides enforced tools to control information security risks. These include safer access management with SAML-based SSO option and better user rights and permissions control with enhanced admin capabilities. Additionally, we introduce optional restrictions: sharing outside of allowed domains and sharing via public link.
In this article:
- Restrict sharing outside the allowed domains
1.1. On Company level
1.2. On Team level - Restrict sharing via public link
2.1. On Company level
2.2. On Team level - Restrict sharing with team and company on Team level
- Restrict ability to move boards to other teams
Restrict sharing outside the allowed domains
✏️ Miro no longer uses the terms "whitelist" or "whitelisted" to refer to a group of domains with specific rights. We now use the terms "allowed domains", "allowlist", and "allowlisted".
Once you restrict sharing outside the allowed domains, Company users will be able to share their boards with users from the specified domains only. With the setting enabled, if a Company user tries to share their board with a domain that is not allowed, they get the following message:
The board cannot be shared with a user whose domain is not in the allowlist
✏️ If sharing via public link is allowed in your Company, public boards can still be accessed by anyone with the board link (and password if it is set up).
Here’s how you can configure the settings on Company and Team level.
On Company level
Set up by: Company Admin
Once you set allowed domains on Company level, the option to share boards outside the domains will be restricted for all company members and teams. Go to Company Settings > Security > Sharing policy and toggle on the Restrict allowed domains option. Add the list of trusted domains used within your Enterprise account.
To let users invite people to boards as non-team collaborators bypassing the allowlist, check the box and click Enable.
The list of trusted domains contains three domains
If some users had been invited to the account before the setting was enabled, you can Verify all users against the allowlist in one click. In case there are users whose domain is not allowed, you can remove them in the following pop-up:
Users whose email addresses do not match the allowlist
On Team level
Set up by: Company Admin
If the settings are configured on Team level, members of a certain team will not be able to invite users outside the allowed domains to the team or boards in it. The option allows you to enable the settings for a particular team without restricting sharing rules for all account users. It also provides you with the option to allow a particular domain for a team without the need to allow it for the whole Company.
✏️ If allowlisted domains are not configured on Team level, Company settings are effective. If Team-level allowlist is configured, this overrides Company-level restrictions. For example, if Domain 1 is allowlisted on Company level and Domain 2 is allowlisted on Team level, Domain 1 will not be allowed on Team level unless it is added on Team-level allowlist.
To configure allowed domains for a particular team, go to Team settings > Permissions and scroll down to Allowed domains for team. Enable the toggle and add allowed domains. To allow sharing with non-team users outside the domains, check the box below.
The option to restrict allowed domains for a particular team in Enterprise account
Restrict sharing via public link
Company admins can restrict all Company users or members of a particular team from sharing company boards publicly. Once the setting is turned off, Anyone with the link option disappears from the Share menu of boards in company or team.
The option to share a board publicly can be hidden on the Share menu
On Company level
Set up by: Company Admin
To restrict public sharing for all Company users, go to Company Settings > Security > Sharing policy and toggle on Sharing via public link - Anyone with the link option will be removed from the board Share menu. All the boards that have been previously shared with a public link or embedded to sites, will become unavailable for public users and their active sessions on the boards will be closed.
To allow sharing company boards publicly (to commenters and viewers without adding them to your teams), the option should be switched on.
If you want to allow sharing company boards publicly for editing, you should also check the checkbox. If you uncheck the checkbox, all of the boards previously shared for public editing will become unavailable for guest editors.
Sharing via public link for viewing, commenting, and editing is enabled
On Team level
Set up by: Company Admin
✏️ Sharing via a public link is turned on by default on Team level and set to “Anyone can view and comment” for newly created teams. However, if this is off on Company level, teams can’t share boards publicly even if it is allowed on Team level.
To restrict sharing boards publicly for certain team users, open Team settings > Permissions and go to Sharing settings. Under the setting By public link, you will see three options: you can choose whether to allow sharing publicly for viewing and commenting only, for viewing, commenting, and editing, or to restrict public sharing for the team.
The option to configure sharing via public link for a team on Enterprise account
Restrict sharing with team and company on Team level
Set up by: Company Admin
✏️ Team and Company-wide sharing is turned on by default if the settings haven't been customized by Company admin.
Enterprise Company admins can not only configure allowed domains and limit public sharing for particular teams within Enterprise subscription but also enable/disable company-wide or team-wide sharing. This is done in Team settings > Permissions > Sharing settings.
Team sharing settings on Enterprise plan
If you allow board sharing with a team, the team members can share their boards and projects with the whole team in one click. When disabled, the option will disappear from the Share menu of the team boards and projects. Previously shared boards and projects won’t be available to team users unless shared with them by other means (board shared via a public link, board shared with the entire company, board is in a project a user also participates, user invited to the board via email).
The option to share board with team is hidden on the Share menu
Company users on account with disabled Team privacy can also share their boards with the whole Company for viewing and commenting in one click. You can lock this option for a particular team by selecting Not allowed under the setting With entire company.
Please note, if Team privacy is enabled in your Company, the option to share boards with entire Company won’t be available even if this is allowed on Team level.
The option to share board with entire company is hidden on the Share menu
Restrict ability to move boards to other teams
Set up by: Company Admin
✏️ Ability to move boards to other teams is turned on by default if the setting hasn't been customized by Company admin.
When a Company admin restricts the option for a team, users won’t be able to move boards into the team and move boards out of the team. The setting is configured for each team in Team settings > Permissions.
The option to restrict moving boards in and out of the team