Single Sign-On (SSO)

Overview

You can configure your Sifflet account to let users sign in using Single Sign-On (SSO) to reduce password fatigue and secure access.

Set Up SSO

Sifflet supports Security Assertion Markup Language 2.0 (SAML2)-based SSO for the following identity providers (IdPs):

Supported IdPs

Supported IdPs

Supported Sign In Methods

Sifflet supports Service-Provider-Initiated (SP-Initiated) SSO: the sign-in process starts on the Sifflet login page.

User Provisioning

You can use Just-In-Time (JIT) user provisioning so that Sifflet automatically provisions users when they sign in to Sifflet for the first time.

JIT user provisioning is turned on by default, but you can turn it off if you want to make sure that only a specific subset of users can access your Sifflet account.

JIT User Provisioning Setting

JIT User Provisioning Setting

Note: If a user was created before their first time logging in with SSO on a tenant with JIT enabled, the user keeps their original permissions and does not inherit JIT default permissions after their first SSO login.

Default Permissions for JIT Users

By default, permissions of JIT-created users are: System Viewer and Domain Viewer on the All domain.

You can customize these permissions however you see fit.

Note: If you do not want users to access any assets after their JIT-based creation, you can create an empty domain and set it as the domain in the default permissions of JIT users.

Alternate Authentication Method

Tick the Allow email/password authentication checkbox to allow users to log in to Sifflet through Single Sign-On (SSO) or username/password.

This setting allows all users with a password to log in to Sifflet through a username/password combination: users who had their password created before this setting was turned on and users who got their password created after this setting was turned on.

Users who did not have their password created by a user or access token with Admin permissions cannot log in through username/password.

Note: To create a password for a user, use the reset password feature in the UI or via the API.

Example Login Page With an Activated “Alternate Authentication Method” Setting

Example Login Page With an Activated “Alternate Authentication Method” Setting


Did this page help you?