기술 자료

Enforce SSO authentication

Require the users in your validated domains to sign in through your identity provider
읽는 시간 2분최근 업데이트: 12일 전

To require that users with email addresses from validated domains use SAML-based SSO when signing in, enforce SSO authentication. As a result, these users can't use password-based authentication or social authentication, except for email addresses that you add to the allowlist. All sign-ins from validated domains go through the configured IdP.
중요
Before enforcing SSO authentication, ensure that you have enabled Enterprise SSO and checked that your SSO configuration works.
To enforce authentication through SSO, complete these steps:
  1. In the Unity Dashboard, open the Account menu and select Manage organization.
  2. In the Administration menu, select SSO & SCIM.
  3. On the Single Sign-on Enforcement tab, under Enforce SSO authentication, turn on the setting.
    The status changes from Not enforced to Enforced.
All users from domains for which SSO is enforced lose access to other sign-in methods, unless they are in the allowlist.
참고
Users whose enterprise domain is from Google Workspace must sign in to Unity with Enterprise SSO and not with their Google social sign-in. Otherwise, Unity SSO enforcement redirects them to their IdP a second time.

Manage exceptions

To allow specific users to bypass SSO authentication enforcement, add their email addresses to the allowlist. You can use the allowlist for external collaborators who don't have an account in your identity provider (IdP), and for accounts and workflows that can't go through SSO.
참고
The allowlist exempts users from SSO authentication enforcement, but not from SCIM provisioning enforcement.
The allowlist can contain only email addresses from validated domains.
For each entry, the allowlist shows the Email, the Reason for the entry, who added it (Added by), and the Date added. To find an entry in a long list, use Search by email.

Add an email address to the allowlist

To add an entry to the allowlist, complete these steps:
  1. In the Unity Dashboard, open the Account menu and select Manage organization.
  2. In the Administration menu, select SSO & SCIM.
  3. On the Single Sign-on Enforcement tab, go to the Allowlisted emails section and select Add email.
  4. Enter an email from a validated domain and a reason.
  5. Select Add.

Remove an email address from the allowlist

To withdraw an exemption, remove the email address from the allowlist:
  1. In the Unity Dashboard, select your profile, and then select Manage organization.
  2. In the Administration menu, select SSO & SCIM.
  3. On the Single Sign-on Enforcement tab, go to the Allowlisted emails section and select the delete icon next to the email address that you want to remove.
  4. In the Delete Allowlist Entry dialog, confirm the deletion.
The user loses their exemption immediately. While SSO authentication enforcement is enabled, they must sign in through your IdP.

Disable SSO authentication enforcement

To stop requiring SSO, turn off Enforce SSO authentication on the Single Sign-on Enforcement tab. The users in your validated domains can then sign in with password-based authentication and social authentication again.
If you have turned on SCIM provisioning enforcement, Unity enforces SSO authentication for you and keeps the setting turned on. To turn off SSO authentication enforcement in that case, first turn off SCIM provisioning enforcement.
Turning off Enterprise SSO also turns off SSO authentication enforcement, along with everything else that depends on Enterprise SSO.

Next steps