Enterprise. Platform administrators control how people sign in and what can be uploaded, from the Security and SSO sections of Sys Config.
Human Verification (Cloudflare Turnstile)
Login, registration and password reset are protected by Cloudflare Turnstile, a lightweight check that tells people from bots, usually without asking anyone to solve a puzzle. It's switched on for the hosted platform. On your own platform, it's configured with a site key and a secret key on the Security tab; the secret is stored encrypted and never shown back.
Rate Limits
Repeated failed logins, password-reset requests and registrations are slowed down. Login attempts are counted per account, so one person guessing at a password can't lock out an entire office sharing one internet connection, with a looser per-connection limit alongside to catch mass attacks. A successful login clears its own count. Each limit can be tuned, or set to 0 to switch it off.
Upload Limits and SVG Handling
Three per-file ceilings, because one number can't suit all three kinds of file:
- images, audio and CSV files (10MB by default)
- video (50MB by default)
- SCORM packages (100MB by default)
These sit alongside each account's plan storage allowance (see Billing & Plans). SVG images are cleaned as they're uploaded: anything that could run code is stripped, a normal design-tool export comes through unchanged, and the uploader is told if something was removed. SVG uploads can also be switched off entirely.
Single Sign-On with Microsoft Entra ID
BLUERABBIT supports SAML Single Sign-On with Microsoft Entra ID (formerly Azure AD), so your people sign in with their work account instead of a separate password. It's available on request for Enterprise and set up per platform together with our team. It's off until then, and while it's off none of the sign-on endpoints exist.
Once it's on:
- The login page shows a sign-in button for your organization (you choose its label).
- Accounts are created on first sign-in from the name and email Entra sends, and land in the default Adventure you pick.
- Accounts are matched on the work identity, not the email address. An existing account with the same email is linked rather than duplicated; an account already linked to a different identity is refused, never guessed.
- Suspended accounts stay out. Suspending someone in User Management blocks their sign-on too, and doesn't create them a fresh account.
Enforcing SSO
You can require Single Sign-On, which hides the password form for everyone. Enforcement only takes effect once the Entra details are actually filled in, so switching it on early can't lock anyone out. God and Admin accounts are the break-glass: they can always sign in with a password, so an outage at the identity provider never leaves the platform without an administrator.