Skip to main content

Signing In to Drata (New Experience)

We are evolving the way you log into Drata to improve security, ensure account verification and simplify the experience for those who have multiple accounts. Depending on your role and number of accounts, your login experience may look a little different. Use the guide below to see what’s changing for you.

Login without SSO

Prerequisites

  • An active Drata account

  • Access to your work email inbox

Sign in with a verification code

  1. Enter your work email address and select Continue.

  2. Drata sends a one-time verification code to that address.

  3. Open the email and copy the verification code.

  4. Return to the login page, paste or type the code, then select Continue.

  5. If you belong to more than one organization or have an account in multiple regions, choose the correct account from the selector.

  6. You’ll be redirected to the Drata application.

If you don’t receive the verification code

  • Check your spam/junk folder.

  • Confirm that you entered the correct work email address (no typos, aliases, or personal email).

  • If the email still doesn’t arrive, ask your IT or security team to:

    • Allowlist Drata email domains and IP addresses.

    • Confirm that your mailbox is not blocking automated emails from Drata.

  • If the problem persists, contact your internal Drata admin or Drata Support.

Login with SSO Configured

Prerequisites

  1. SSO must be configured for your organization.

  2. You must have an active account in your organization’s IdP.

Sign in with SSO (Single Tenant)

For users whose organizations require SSO to access Drata and admins who manage or support SSO-based access.

Sign in to Drata using your organization’s single sign-on (SSO) provider. Use this method if your company requires authentication through an identity provider (IdP) such as Okta, Microsoft, Google, or another SAML-based provider.

  1. Enter your work email address and select Continue.

  2. If SSO is enabled for your domain, Drata will:

    • Redirect you to your IdP (for example, Google, Microsoft, Okta, or OneLogin), or

    • Show you one or more SSO options (for example, Continue with Google).

  3. Complete any sign-in and multi-factor authentication (MFA) steps required by your IdP.

  4. After successful authentication, Drata sends you back to the login service to confirm your identity.

  5. If you have access to more than one organization or workspace, choose the correct account from the selector.

  6. You’ll be redirected into Drata.

Sign in with SSO (Multi-tenant)

For users with access to multiple tenants verify their email address before signing in with SSO.

  1. Enter your work email address and select Continue.

  2. Drata sends a one-time verification code to that address.

  3. Open the email and copy the verification code.

  4. Return to the login page, paste or type the code, then select Continue.

  5. Choose the correct account from the selector.

  6. If SSO is enabled for that account, Drata will:

    • Redirect you to your IdP (for example, Google, Microsoft, Okta, or OneLogin), or

    • Show you one or more SSO options if you have multiple IdPs configured.

  7. Complete any sign-in and multi-factor authentication (MFA) steps required by your IdP.

  8. You’ll be redirected into Drata.

Log In to My Drata (Employee Login)

With the release of the new experience, Employees only have access to the new Drata Experience.

  1. Login to My Drata: Select the login link provided in your email invitation

  2. Sign In: Enter your email and securely log in using your company’s Single Sign-On (SSO) or by using your work email and a secure one-time authentication code.

  3. Explore My Drata: You will automatically land in the New My Drata Experience.

Frequently Asked Questions (FAQ)

I authenticated via email rather than SSO. Is this an issue?

No, both authentication methods are fully supported and secure. While Single Sign-On (SSO) is often preferred for streamlined access and reduced re-authentication, using your email and a unique verification code is a valid alternative.

My admin is on Classic, but what about my employees?

Regardless of whether an admin is on Classic or the New Experience, all employees with employee-only roles are always routed to My Drata in the New Experience.

Basic troubleshooting steps

If you are not receiving your one-time password (OTP) when trying to sign in to Drata, start with the basic checks below. These steps can help rule out common email delivery and browser-related issues.

  • Check your spam or junk folder for an email from [email protected]. This is a common first step when expected Drata emails do not appear in the inbox.

  • Confirm that [email protected] is not blocked, blacklisted, or being filtered by your email system. If your company uses email security tooling, your IT team may need to allowlist this sender.

  • Try signing in from an incognito or private browser window. This can help rule out cached sessions, browser extensions, or stored cookies that may interfere with the sign-in flow.

  • If you are connected to a VPN, disconnect from it temporarily and try again. In some cases, network routing or security settings can interfere with login or email delivery.

If you still do not receive the OTP

If the OTP still does not arrive after completing the steps above, contact your internal IT or email administrator to verify that messages from [email protected] are not being quarantined or blocked.

Did this answer your question?