getsentry / getsentry/sentry

Auth - Azure SSO SCIM: Once users enable 2FA the unchangeable state of the user account gets removed

Open
#77,625 3 comments 1 reaction 0 assignees View on GitHub
Bug Product Area: Settings - Auth Sync: Jira
Dominant language
Python
Stars
44.8k
Forks
4.9k
Avg merge
22h 21m
Merged PRs (30d)
586

Description

### Environment

SaaS (https://sentry.io/)

### Steps to Reproduce

1. Enable SSO + SCIM
2. Provision the user from SCIM
3. User enables 2FA

This makes it possible again that the org owner or own user can remove the user account which should not be possible

### Expected Result

We would like to enforce 2FA, but can't at the moment as this will likely result in some unwanted behaviour in user management. It is possible to reconnect the user to Sentry, but they will end up without any Team. A Group Sync from AzureAD/EntraID, or removing and adding a user back to the group does not seem to fix this

### Actual Result

enabling 2FA removes this restriction from SCIM

### Product Area

Settings - Auth

### Link

_No response_

### DSN

_No response_

### Version

_No response_

┆Issue is synchronized with this [Jira Improvement](https://getsentry.atlassian.net/browse/FEEDBACK-2295) by [Unito](https://www.unito.io)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.