mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 14:28:20 +00:00
Merge pull request #3652 from Infisical/ENG-2817
Update docs and some UI to make Admin SSO bypass more clear
This commit is contained in:
@@ -70,7 +70,7 @@ description: "Learn how to configure Auth0 OIDC for Infisical SSO."
|
|||||||
prior to enforcing OIDC SSO to prevent any unintended issues.
|
prior to enforcing OIDC SSO to prevent any unintended issues.
|
||||||
</Warning>
|
</Warning>
|
||||||
<Info>
|
<Info>
|
||||||
In case of a lockout, an organization admin can use the admin login portal in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
In case of a lockout, an organization admin can use the [Admin Login Portal](https://infisical.com/docs/documentation/platform/sso/overview#admin-login-portal) in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
||||||
</Info>
|
</Info>
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|||||||
@@ -76,7 +76,7 @@ description: "Learn how to configure Auth0 SAML for Infisical SSO."
|
|||||||
Once you've completed this requirement, you can toggle the **Enforce SAML SSO** button to enforce SAML SSO.
|
Once you've completed this requirement, you can toggle the **Enforce SAML SSO** button to enforce SAML SSO.
|
||||||
|
|
||||||
<Info>
|
<Info>
|
||||||
In case of a lockout, an organization admin can use the admin login portal in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
In case of a lockout, an organization admin can use the [Admin Login Portal](https://infisical.com/docs/documentation/platform/sso/overview#admin-login-portal) in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
||||||
</Info>
|
</Info>
|
||||||
</Step>
|
</Step>
|
||||||
|
|
||||||
|
|||||||
@@ -109,7 +109,7 @@ description: "Learn how to configure Microsoft Entra ID for Infisical SSO."
|
|||||||
prior to enforcing SAML SSO to prevent any unintended issues.
|
prior to enforcing SAML SSO to prevent any unintended issues.
|
||||||
</Warning>
|
</Warning>
|
||||||
<Info>
|
<Info>
|
||||||
In case of a lockout, an organization admin can use the admin login portal in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
In case of a lockout, an organization admin can use the [Admin Login Portal](https://infisical.com/docs/documentation/platform/sso/overview#admin-login-portal) in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
||||||
</Info>
|
</Info>
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|||||||
@@ -70,7 +70,7 @@ Prerequisites:
|
|||||||
We recommend ensuring that your account is provisioned using the identity provider prior to enforcing OIDC SSO to prevent any unintended issues.
|
We recommend ensuring that your account is provisioned using the identity provider prior to enforcing OIDC SSO to prevent any unintended issues.
|
||||||
</Warning>
|
</Warning>
|
||||||
<Info>
|
<Info>
|
||||||
In case of a lockout, an organization admin can use the admin login portal in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
In case of a lockout, an organization admin can use the [Admin Login Portal](https://infisical.com/docs/documentation/platform/sso/overview#admin-login-portal) in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
||||||
</Info>
|
</Info>
|
||||||
</Step>
|
</Step>
|
||||||
|
|
||||||
|
|||||||
@@ -84,7 +84,7 @@ description: "Learn how to configure Google SAML for Infisical SSO."
|
|||||||
prior to enforcing SAML SSO to prevent any unintended issues.
|
prior to enforcing SAML SSO to prevent any unintended issues.
|
||||||
</Warning>
|
</Warning>
|
||||||
<Info>
|
<Info>
|
||||||
In case of a lockout, an organization admin can use the admin login portal in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
In case of a lockout, an organization admin can use the [Admin Login Portal](https://infisical.com/docs/documentation/platform/sso/overview#admin-login-portal) in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
||||||
</Info>
|
</Info>
|
||||||
</Step>
|
</Step>
|
||||||
|
|
||||||
|
|||||||
@@ -85,11 +85,10 @@ description: "Learn how to configure JumpCloud SAML for Infisical SSO."
|
|||||||
Once you've completed this requirement, you can toggle the **Enforce SAML SSO** button to enforce SAML SSO.
|
Once you've completed this requirement, you can toggle the **Enforce SAML SSO** button to enforce SAML SSO.
|
||||||
|
|
||||||
<Warning>
|
<Warning>
|
||||||
We recommend ensuring that your account is provisioned the application in JumpCloud
|
We recommend ensuring that your account is provisioned in the application in JumpCloud prior to enforcing SAML SSO to prevent any unintended issues.
|
||||||
prior to enforcing SAML SSO to prevent any unintended issues.
|
|
||||||
</Warning>
|
</Warning>
|
||||||
<Info>
|
<Info>
|
||||||
In case of a lockout, an organization admin can use the admin login portal in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
In case of a lockout, an organization admin can use the [Admin Login Portal](https://infisical.com/docs/documentation/platform/sso/overview#admin-login-portal) in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
||||||
</Info>
|
</Info>
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|||||||
@@ -97,7 +97,7 @@ description: "Learn how to configure Keycloak OIDC for Infisical SSO."
|
|||||||
prior to enforcing OIDC SSO to prevent any unintended issues.
|
prior to enforcing OIDC SSO to prevent any unintended issues.
|
||||||
</Warning>
|
</Warning>
|
||||||
<Info>
|
<Info>
|
||||||
In case of a lockout, an organization admin can use the admin login portal in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
In case of a lockout, an organization admin can use the [Admin Login Portal](https://infisical.com/docs/documentation/platform/sso/overview#admin-login-portal) in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
||||||
</Info>
|
</Info>
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|||||||
@@ -83,7 +83,7 @@ description: "Learn how to configure Keycloak SAML for Infisical SSO."
|
|||||||
|
|
||||||

|

|
||||||
|
|
||||||
Set the the **Name** field to **Username**, the **Property** field to **username**, and the **SAML Attribtue Name** to **username**.
|
Set the the **Name** field to **Username**, the **Property** field to **username**, and the **SAML Attribute Name** to **username**.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
@@ -128,7 +128,7 @@ description: "Learn how to configure Keycloak SAML for Infisical SSO."
|
|||||||
prior to enforcing SAML SSO to prevent any unintended issues.
|
prior to enforcing SAML SSO to prevent any unintended issues.
|
||||||
</Warning>
|
</Warning>
|
||||||
<Info>
|
<Info>
|
||||||
In case of a lockout, an organization admin can use the admin login portal in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
In case of a lockout, an organization admin can use the [Admin Login Portal](https://infisical.com/docs/documentation/platform/sso/overview#admin-login-portal) in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
||||||
</Info>
|
</Info>
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|||||||
@@ -93,13 +93,12 @@ description: "Learn how to configure Okta SAML 2.0 for Infisical SSO."
|
|||||||
Once you've completed this requirement, you can toggle the **Enforce SAML SSO** button to enforce SAML SSO.
|
Once you've completed this requirement, you can toggle the **Enforce SAML SSO** button to enforce SAML SSO.
|
||||||
|
|
||||||
<Warning>
|
<Warning>
|
||||||
We recommend ensuring that your account is provisioned the application in Okta
|
We recommend ensuring that your account is provisioned for the application in Okta prior to enforcing SAML SSO to prevent any unintended issues.
|
||||||
prior to enforcing SAML SSO to prevent any unintended issues.
|
|
||||||
</Warning>
|
</Warning>
|
||||||
<Info>
|
|
||||||
In case of a lockout, an organization admin can use the admin login portal in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
|
||||||
</Info>
|
|
||||||
|
|
||||||
|
<Info>
|
||||||
|
In case of a lockout, an organization admin can use the [Admin Login Portal](https://infisical.com/docs/documentation/platform/sso/overview#admin-login-portal) in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
||||||
|
</Info>
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|
||||||
|
|||||||
@@ -39,18 +39,30 @@ If your required identity provider is not shown in the list above, please reach
|
|||||||
For enhanced security, Infisical enforces PKCE (Proof Key for Code Exchange) with the OAuth 2.0-based SSO providers and OIDC. This provides additional protection against authorization code interception attacks and strengthens your authentication flow security.
|
For enhanced security, Infisical enforces PKCE (Proof Key for Code Exchange) with the OAuth 2.0-based SSO providers and OIDC. This provides additional protection against authorization code interception attacks and strengthens your authentication flow security.
|
||||||
</Info>
|
</Info>
|
||||||
|
|
||||||
|
## SSO Break Glass
|
||||||
|
|
||||||
|
In the event your SSO provider experiences downtime, and you need to access Infisical, Organization Admins can utilize the Admin Login Portal to bypass SSO enforcement.
|
||||||
|
|
||||||
|
This portal is accessible at `/login/admin` (e.g., https://app.infisical.com/login/admin).
|
||||||
|
|
||||||
|
<Note>
|
||||||
|
To bypass SSO for an organization, you must be an **Organization Admin** for that specific organization. This **Organization Admin** role is independent of **Server Admin** status. Being a **Server Admin** alone does not grant permission to use this bypass feature.
|
||||||
|
</Note>
|
||||||
|
|
||||||
## FAQ
|
## FAQ
|
||||||
|
|
||||||
<AccordionGroup>
|
<AccordionGroup>
|
||||||
<Accordion title="Why does Infisical require additional email verification for users connected via SAML?">
|
<Accordion title="Why does Infisical require additional email verification for users connected via SAML?">
|
||||||
By default, Infisical Cloud is configured to not trust emails from external
|
By default, Infisical Cloud is configured to not trust emails from external
|
||||||
identity providers to prevent any malicious account takeover attempts via
|
identity providers to prevent any malicious account takeover attempts via
|
||||||
email spoofing. Accordingly, Infisical creates a new user for anyone provisioned
|
email spoofing. Accordingly, Infisical creates a new user for anyone provisioned
|
||||||
through an external identity provider and requires an additional email
|
through an external identity provider and requires an additional email
|
||||||
verification step upon their first login.
|
verification step upon their first login.
|
||||||
|
|
||||||
If you're running a self-hosted instance of Infisical and would like it to trust emails from external identity providers,
|
If you're running a self-hosted instance of Infisical and would like it to trust emails from external identity providers,
|
||||||
you can configure this behavior in the Server Admin Console.
|
you can configure this behavior in the Server Admin Console.
|
||||||
|
</Accordion>
|
||||||
</Accordion>
|
<Accordion title="Why do I get redirected to SSO when trying to use the Admin Login Portal?">
|
||||||
|
You are likely being redirected because you do not have email authentication mode enabled, or you're not an **Organization Admin**. This portal requires **Organization Admin** status and direct credential login (email and password). **Server Admin** status alone is insufficient.
|
||||||
|
</Accordion>
|
||||||
</AccordionGroup>
|
</AccordionGroup>
|
||||||
|
|||||||
+10
-1
@@ -129,7 +129,16 @@ export const OrgGeneralAuthSection = () => {
|
|||||||
level.
|
level.
|
||||||
</span>
|
</span>
|
||||||
<p className="mt-4">
|
<p className="mt-4">
|
||||||
In case of a lockout, admins can use the admin login portal at{" "}
|
In case of a lockout, admins can use the{" "}
|
||||||
|
<a
|
||||||
|
target="_blank"
|
||||||
|
className="underline underline-offset-2 hover:text-mineshaft-300"
|
||||||
|
href="https://infisical.com/docs/documentation/platform/sso/overview#admin-login-portal"
|
||||||
|
rel="noreferrer"
|
||||||
|
>
|
||||||
|
Admin Login Portal
|
||||||
|
</a>{" "}
|
||||||
|
at{" "}
|
||||||
<a
|
<a
|
||||||
target="_blank"
|
target="_blank"
|
||||||
rel="noopener noreferrer"
|
rel="noopener noreferrer"
|
||||||
|
|||||||
@@ -212,7 +212,16 @@ export const OrgOIDCSection = (): JSX.Element => {
|
|||||||
level.
|
level.
|
||||||
</span>
|
</span>
|
||||||
<p className="mt-4">
|
<p className="mt-4">
|
||||||
In case of a lockout, admins can use the admin login portal at{" "}
|
In case of a lockout, admins can use the{" "}
|
||||||
|
<a
|
||||||
|
target="_blank"
|
||||||
|
className="underline underline-offset-2 hover:text-mineshaft-300"
|
||||||
|
href="https://infisical.com/docs/documentation/platform/sso/overview#admin-login-portal"
|
||||||
|
rel="noreferrer"
|
||||||
|
>
|
||||||
|
Admin Login Portal
|
||||||
|
</a>{" "}
|
||||||
|
at{" "}
|
||||||
<a
|
<a
|
||||||
target="_blank"
|
target="_blank"
|
||||||
rel="noopener noreferrer"
|
rel="noopener noreferrer"
|
||||||
|
|||||||
Reference in New Issue
Block a user