Add a non-SSO user to an SSO-only org

When an organization enforces SSO, every user signs in through the identity provider. To keep specific accounts, such as service accounts, on email-and-password sign-in, add them to the non-SSO users list in the SSO settings.

How SSO enforcement affects user access

When Enforce users to login to Kobiton only through SSO is enabled:

  • Every user signs in through SSO unless they are on the non-SSO users list.

  • Kobiton removes every user’s stored password, including the passwords of users later added to the non-SSO users list.

  • Kobiton turns off the Invite button on Org Management > Users.

  • The Create org member API returns a 400 error with the message Cannot invite new user because the organization enforces its users to login/signup to Kobiton only through SSO.

If SSO enforcement is turned off later, users whose passwords were removed must reset their password through Forgot Password? before signing in with email and password.

Add an existing user to the non-SSO users list

Keep at least one org admin on the non-SSO users list. If SSO becomes unavailable, users on this list are the only accounts that can still sign in to Kobiton Portal.

  1. Sign in to Kobiton Portal with an account that has the org_setting.modify_sso_setting permission.

  2. Select the profile picture and choose Settings, then choose SSO Settings.

  3. Scroll to Verify Configuration (panel 4).

  4. Under Choose users who are allowed to login without SSO, add the user in the Add Users.. field.

    The Choose users who are allowed to login without SSO field in the Verify Configuration panel

  5. Select Save.

Reset the password and sign in

A user added to the non-SSO users list must reset their password before their first email-and-password sign-in. The non-SSO user completes these steps.

  1. Open Kobiton Portal.

  2. Enter the username or email, and then select Forgot Password?.

  3. Enter the username or email again.

    Kobiton sends a password reset email to the address on the account.

  4. Open the link in the email and set a new password.

  5. Sign in to Kobiton Portal with the new password.