heroku / heroku/roadmap

Allow for disabling of non-SSO logins

Open
#341 1 comment 1 reaction 1 assignee Claimed by @asigismoheroku View on GitHub
Proposed
Dominant language
No language data
Stars
225
Forks
19
PR merge metrics
No merged PRs in 30d

Description

### Required Terms

- [x] I agree to follow this project's [Code of Conduct](https://github.com/heroku/roadmap/blob/main/CODE_OF_CONDUCT.md)
- [x] I have read and accept the [Salesforce Program Agreement](https://www.salesforce.com/company/program-agreement/)

### What service(s) is this request for?

Heroku Identity Management

### Tell us about what you're trying to solve. What challenges are you facing?

Currently, even after enabling SSO for our Heroku organization, users are able to sign in without SSO if permissions have been assigned to their email addresses. This allows users who are not managed by our identity provider to retain access, which poses a security risk and could result in unauthorised or forgotten accounts with lingering access.

Request:
We need the ability to enforce SSO-only access for our organization, so that all users must authenticate via our identity provider. Disabling non-SSO logins would ensure that only managed accounts can access Heroku, improving our security and compliance posture.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.