Enforce SSO authentication
Require the users in your validated domains to sign in through your identity provider
阅读时间2 分钟最后更新于 12 天前
To require that users with email addresses from validated domains use SAML-based SSO when signing in, enforce SSO authentication. As a result, these users can't use password-based authentication or social authentication, except for email addresses that you add to the allowlist. All sign-ins from validated domains go through the configured IdP.
To enforce authentication through SSO, complete these steps:
-
In the Unity Dashboard, open the Account menu and select Manage organization.
-
In the Administration menu, select SSO & SCIM.
-
On the Single Sign-on Enforcement tab, under Enforce SSO authentication, turn on the setting.The status changes from Not enforced to Enforced.
All users from domains for which SSO is enforced lose access to other sign-in methods, unless they are in the allowlist.
Manage exceptions
To allow specific users to bypass SSO authentication enforcement, add their email addresses to the allowlist. You can use the allowlist for external collaborators who don't have an account in your identity provider (IdP), and for accounts and workflows that can't go through SSO.
The allowlist can contain only email addresses from validated domains.
For each entry, the allowlist shows the Email, the Reason for the entry, who added it (Added by), and the Date added. To find an entry in a long list, use Search by email.
Add an email address to the allowlist
To add an entry to the allowlist, complete these steps:
- In the Unity Dashboard, open the Account menu and select Manage organization.
- In the Administration menu, select SSO & SCIM.
- On the Single Sign-on Enforcement tab, go to the Allowlisted emails section and select Add email.
- Enter an email from a validated domain and a reason.
- Select Add.
Remove an email address from the allowlist
To withdraw an exemption, remove the email address from the allowlist:
- In the Unity Dashboard, select your profile, and then select Manage organization.
- In the Administration menu, select SSO & SCIM.
- On the Single Sign-on Enforcement tab, go to the Allowlisted emails section and select the delete icon next to the email address that you want to remove.
- In the Delete Allowlist Entry dialog, confirm the deletion.
The user loses their exemption immediately. While SSO authentication enforcement is enabled, they must sign in through your IdP.
Disable SSO authentication enforcement
To stop requiring SSO, turn off Enforce SSO authentication on the Single Sign-on Enforcement tab. The users in your validated domains can then sign in with password-based authentication and social authentication again.
If you have turned on SCIM provisioning enforcement, Unity enforces SSO authentication for you and keeps the setting turned on. To turn off SSO authentication enforcement in that case, first turn off SCIM provisioning enforcement.
Turning off Enterprise SSO also turns off SSO authentication enforcement, along with everything else that depends on Enterprise SSO.