# Different default SSO organization based on Domain

**URL:** https://forum.pritunl.com/t/different-default-sso-organization-based-on-domain/957
**Category:** Pritunl VPN
**Tags:** pritunl
**Created:** [April 13, 2023, 11:59am UTC](https://forum.pritunl.com/t/different-default-sso-organization-based-on-domain/957 "2023-04-13T11:59:57Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![Tracing7565](https://forum.pritunl.com/letter_avatar_proxy/v4/letter/t/bbe5ce/32.png) [@Tracing7565](https://forum.pritunl.com/u/Tracing7565)
#### Post date: [April 13, 2023, 11:59am UTC](https://forum.pritunl.com/t/different-default-sso-organization-based-on-domain/957/1 "2023-04-13T11:59:57Z")

</div>

Hello,

currently I am using awesome Google Apps + Duo SSO for managing access to internal network to employees.

Now, we are hiring contractors, which will use domain `ext.something.com` instead of `something.com`. I have created a new Pritunl Organization with different routes for contractors, but I want to have same SSO 2FA security. Right now, if I add another Google Apps Domain (`ext.something.com`) into Pritunl, it will use default SSO Organization.

But that is not what I need. I need to somehow force new SSO signups to use different orgs based on the domain name.

What is the best way to do that?

I would be OK manually registering people into another org, but then they would use PIN auth instead of SSO + 2FA.

Thanks!

---

<div class="post-metadata">

### Author: ![zach](https://forum.pritunl.com/user_avatar/forum.pritunl.com/zach/32/1105_2.png) [@zach](https://forum.pritunl.com/u/zach)
#### Post date: [April 13, 2023, 6:15pm UTC](https://forum.pritunl.com/t/different-default-sso-organization-based-on-domain/957/2 "2023-04-13T18:15:36Z")

</div>

Users are added to organizations if the user has a Google Workspace group name that matches an existing organization name. When manually adding users the user type must be changed in the advanced user settings.
