-
Notifications
You must be signed in to change notification settings - Fork 949
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update sso-overview.md to describe disabling password logins for admins #6100
Conversation
The latest updates on your projects. Learn more about Vercel for Git ↗︎
|
I can add this if we're sure want it, but we're not using it for any other SSO settings, and our docs instruct using them sparingly, so I'm a little hesitant. @dbt-labs/product-docs, what do you think?
@nehahystad, If we're considering this best practice, it contradicts our existing item in the list of "Identity Provider is down — Account admins will continue to be able to log in with a password which would allow them to work with your Identity Provider to troubleshoot the problem." Should that one be removed/replaced with your suggested line? |
Sounds good on the screenshot — we can follow the best practice here! Good call out on the security best practices. I think we should remove the one about Account admins being able to login and replace it with the recommendation to enforce SSO for all users. Unless you know of cases where the account admin being able to login really helped them troubleshoot an issue with SSO? |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thank you @asmclean I think a screenshot would be a good idea. We try not to go overboard on them, but we do have actionable feedback from clients that they would be helpful regarding setup instructions or account settings feature locations. I can take it up as a follow-up item and see where we can enhance the SSO overview page as a whole.
Sounds good; thanks for the feedback, @matthewshaver. I did not yet make a change to the best practices section that @nehahystad and I were discussing, so hopefully that can be included in your follow-up as well. |
What are you changing in this pull request and why?
Add information about the the new checkbox to control whether or not administrators can login via password once SSO is configured.
Checklist