Skip to Main Content

Share your product feedback

Status Future consideration
Categories User management
Created by Angela Frey
Created on Feb 9, 2024

Manage SSO user access in Aha - not from IdP

Who would benefit?

Aha Admins, IT teams

What impact would it make?

Simplify user management

How should it work?

Currently, if I have SSO on my idea portals then employees can access any portal that the SSO is connected to. I am not able to, say, allow "all employees" to access the internal employee idea portal but limit "passed the training" access to a secondary customer-facing portal.

Also, currently I can't both have SSO and "gatekeep" access based on folks passing a training - if I did want to limit access, I would have to burden my IT team and bottleneck my process by managing access in the IdP.


In other words, just because I want to use SSO for authentication does not mean I want to manage access permissions through that IdP. Like the admin side, I want to be able to specify permission to access from the Users page of each Idea Portal.

  • Attach files
  • Rob Hale
    Reply
    |
    Jul 28, 2024

    This has become a real issue for us as we want to launch numerous internal portals to different audiences that will evolve over time. We want to have the ability to self-administer platform access and not have to make ongoing auth admin requests of IT. Hopefully this is a relatively straightforward change as there is pre-existing logic within the Ideas portal configuration to add users. The logic could then be to default to SSO (if configured) but restrict to those user IDs listed in the portal config.