Enforement of SSO for multiple domains
If we want to have Enforce SSO for multiple domains, we must currently:
Provision a user with the domain
Have the user sign-in with SSO
Assign the user Owner role (which may not be appropriate for the user) and have them toggle "Enforce SSO"
This activity should be accessible and doable by any Sync owner/admin centrally and not require a user signed in using the domain with the owner role assigned. This is a security risk even for a short period of time.
3
1 reply