Update docs and some UI to make Admin SSO bypass more clear

This commit is contained in:
x032205
2025-05-23 18:47:33 -04:00
parent 5518df116f
commit 6369d13862
12 changed files with 119 additions and 89 deletions

View File

@@ -39,18 +39,30 @@ If your required identity provider is not shown in the list above, please reach
For enhanced security, Infisical enforces PKCE (Proof Key for Code Exchange) with the OAuth 2.0-based SSO providers and OIDC. This provides additional protection against authorization code interception attacks and strengthens your authentication flow security.
</Info>
## Admin Login Portal
Organization Admins can utilize the Admin Login Portal to bypass SSO enforcement in case of an emergency.
This portal is accessible at `/login/admin` (e.g., https://app.infisical.com/login/admin).
<Note>
This bypass functionality is exclusively available to **Organization Admins**. **Server Admins** are not permitted to use this feature.
</Note>
## FAQ
<AccordionGroup>
<Accordion title="Why does Infisical require additional email verification for users connected via SAML?">
By default, Infisical Cloud is configured to not trust emails from external
identity providers to prevent any malicious account takeover attempts via
email spoofing. Accordingly, Infisical creates a new user for anyone provisioned
through an external identity provider and requires an additional email
verification step upon their first login.
<Accordion title="Why does Infisical require additional email verification for users connected via SAML?">
By default, Infisical Cloud is configured to not trust emails from external
identity providers to prevent any malicious account takeover attempts via
email spoofing. Accordingly, Infisical creates a new user for anyone provisioned
through an external identity provider and requires an additional email
verification step upon their first login.
If you're running a self-hosted instance of Infisical and would like it to trust emails from external identity providers,
you can configure this behavior in the Server Admin Console.
</Accordion>
If you're running a self-hosted instance of Infisical and would like it to trust emails from external identity providers,
you can configure this behavior in the Server Admin Console.
</Accordion>
<Accordion title="Why do I get redirected to SSO when trying to use the Admin Login Portal?">
You are likely being redirected because you're not using your username and password, or you're not an **Organization Admin**. This portal requires **Organization Admin** status and direct credential login (username and password). **Server Admin** status alone is insufficient.
</Accordion>
</AccordionGroup>