> ## Documentation Index
> Fetch the complete documentation index at: https://help.dingtalk.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Sign In to DingTalk and DingMail with SSO

> Step-by-step guide to signing in to DingTalk and DingMail with single sign-on (SSO), using JumpCloud as the IDaaS example — from organization code to MFA verification.

If your organization has enabled single sign-on (SSO), you can use your work email account to sign in to DingTalk and DingMail — no separate password is needed for each product. This guide walks you through SSO sign-in in DingTalk, using **JumpCloud** as an example identity-as-a-service (IDaaS) provider. DingMail shares the same enterprise identity system, so sign-in works the same way when SSO is enabled.

<Note>
  The sign-in pages displayed during DingTalk sign-in vary slightly across IDaaS platforms (such as JumpCloud, Okta, Microsoft Entra ID, and Google Workspace), but the overall flow is the same (organization code → email and password → additional verification). If your organization uses a provider other than JumpCloud, follow the prompts on your actual sign-in page.
</Note>

## Before you begin

Before signing in, check with your IT admin for the following information:

* Your **organization code** (provided by your IT admin to identify your company account).
* Your **work email account and password**.
* The **JumpCloud Protect** app or another authenticator app installed on your mobile device. If it is not installed yet, you will be guided through the installation and binding during your first sign-in.

## Sign in to DingTalk

<Steps>
  <Step title="Download and install DingTalk">
    Download the client for your platform from [www.dingtalk.io/download](https://www.dingtalk.io/download/). Supported platforms include Windows, macOS, iOS, and Android. Choose the version that matches your device.
  </Step>

  <Step title="Continue with Enterprise Account">
    Open DingTalk after installation. On the sign-in page, select **Continue with Enterprise Account**.

    ![Continue with Enterprise Account](https://img.alicdn.com/imgextra/i4/O1CN01uD6mF7m6SxL1901G_!!6000000005855-2-tps-564-802.png)
  </Step>

  <Step title="Enter your organization code">
    In the dialog that appears, enter the **organization code** provided by your IT admin, then click **Next**.

    <Note>
      The organization code is a unique identifier issued by your IT admin after your organization enables SSO. Do not use someone else's organization code. If you lose or forget it, contact your IT department to get a new one.
    </Note>

    ![Enter your organization code](https://img.alicdn.com/imgextra/i3/O1CN01CE873fNM7fL1kGIY_!!6000000005298-2-tps-860-1218.png)
  </Step>

  <Step title="Enter your work email and password">
    Enter your **work email address** and **email password**, then click **SSO Login**.

    ![Enter your work email and password](https://img.alicdn.com/imgextra/i2/O1CN01MtxzB84yeuH4YTra_!!6000000001929-2-tps-2244-1050.png)

    <Note>
      The email and password here are managed by your organization's identity service (IDaaS, for example JumpCloud) and are not related to the DingTalk account system. If you forget your password, reset it through the **Forgot password** process of your company's IT system.
    </Note>
  </Step>

  <Step title="Choose a verification method">
    After you click **SSO Login**, if your organization requires multi-factor authentication (MFA), the Set Up MFA page appears. Select **JumpCloud Protect** from the list of MFA methods, and then click **Continue**. On the next page, select **I Have the App**.

    ![Choose a verification method](https://img.alicdn.com/imgextra/i2/O1CN01z0ugaABN9BK2Nmu0_!!6000000000714-2-tps-1174-1026.png)

    <Note>
      If this is your **first sign-in** and the JumpCloud Protect app is not installed yet, the page will guide you to download JumpCloud Protect or another compatible authenticator app (such as Google Authenticator or Microsoft Authenticator) on your phone and complete the binding. Follow the on-screen prompts to finish the installation and first-time binding, then return to this step.
    </Note>
  </Step>

  <Step title="Enter the verification code to finish sign-in">
    Open the **JumpCloud Protect app** on your phone and follow these steps to get a one-time verification code. If this is your first-time binding, tap **Add Account** and scan the **QR code** shown on the DingTalk sign-in page to complete device binding.

    1. Find and tap the DingTalk entry to open the one-time verification code page.
    2. Check the 6-digit verification code displayed on the screen. It is usually valid for 30 seconds.
    3. Enter the 6-digit verification code into the verification code field of the DingTalk desktop sign-in window, then click **Confirm**.
    4. After verification succeeds, your account is signed in with SSO.

    <Note>
      For security reasons, authenticator apps generally do not allow screenshots of the verification code page, so no screenshot is provided for this step. Follow the instructions above on your phone instead.
    </Note>

    ![Enter the verification code](https://img.alicdn.com/imgextra/i4/O1CN01iqewn5AmZ4L1fjJc_!!6000000001505-2-tps-824-1156.png)
  </Step>

  <Step title="Start a direct message">
    After signing in, you can find members of your organization in DingTalk and start a conversation:

    1. Click the search bar at the top of DingTalk desktop.
    2. Type the contact's name.
    3. Select the contact from the search results.
    4. Type your message in the input box.
    5. Press **Enter** or click **Send**.

    ![Start a direct message](https://img.alicdn.com/imgextra/i3/O1CN0112YBKg6sj6J43lZz_!!6000000002638-2-tps-2000-1227.png)
  </Step>
</Steps>

## Sign in to DingMail

<Steps>
  <Step title="Open Mail and enter your DingMail address">
    Open DingTalk desktop, click **Mail** in the left sidebar, enter your **DingMail address**, then click **Continue**.

    ![Open Mail and enter your DingMail address](https://img.alicdn.com/imgextra/i3/O1CN01kMhQOtcEb5K45HDo_!!6000000001514-2-tps-2012-1176.png)
  </Step>

  <Step title="Enter your work email">
    Enter your work **email address** (not a DingMail address), then click **Continue**.

    ![Enter your work email](https://img.alicdn.com/imgextra/i3/O1CN015geOMVThieB4C4gK_!!6000000001172-2-tps-2066-1214.png)
  </Step>

  <Step title="Enter your email password">
    Enter your **email password**, then click **SSO Login**.

    ![Enter your email password](https://img.alicdn.com/imgextra/i4/O1CN01gJiI9d3UqHG3TVms_!!6000000007922-2-tps-1712-1002.png)
  </Step>

  <Step title="Enter the verification code">
    Enter the 6-digit verification code from your authenticator app.

    ![Enter the verification code](https://img.alicdn.com/imgextra/i2/O1CN01oCGrpMBpJsH42VW2_!!6000000007523-2-tps-1990-1160.png)
  </Step>

  <Step title="Start using DingMail">
    After verification succeeds, **DingMail** is ready to use.

    ![DingMail is ready to use](https://img.alicdn.com/imgextra/i2/O1CN01iqDDqnRpKgC3i78y_!!6000000001097-2-tps-1828-1076.png)
  </Step>
</Steps>

## FAQ

<AccordionGroup>
  <Accordion title="I did not receive an organization code. What should I do?">
    Contact your IT admin. Organization codes are assigned by the enterprise admin when your organization activates DingTalk Enterprise Edition.
  </Accordion>

  <Accordion title="I forgot my email password. What should I do?">
    The password used for SSO sign-in is managed by your organization's IDaaS platform (such as JumpCloud), not by DingTalk. Reset it through the "Forgot password" process of your company's IT system, or contact your IT admin for help.
  </Accordion>

  <Accordion title="The verification code from JumpCloud Protect is rejected">
    TOTP verification codes refresh every 30 seconds. Make sure that:

    * Time on your phone is set to sync automatically.
    * You enter the code before it expires.
    * You selected the correct entry for the account you are signing in with.
  </Accordion>

  <Accordion title="JumpCloud Protect stops working after I switch phones">
    Contact your IT admin to reset your MFA binding in the JumpCloud console, then scan the QR code again on your new phone to rebind.
  </Accordion>

  <Accordion title="My organization does not use JumpCloud. Can I still follow this guide?">
    The overall flow is the same (organization code → email and password → verification code), but the sign-in authorization pages look different depending on the IDaaS provider (Okta, Microsoft Entra ID, Google Workspace, and so on). Follow the prompts on your actual page, or contact your IT department.
  </Accordion>
</AccordionGroup>
