I have an active session in IDP, but every time I try to log in to Oneflow, I have to provide my IDP credentials. Is it possible to log in once and keep being logged in? Yes it is possible, please ask your CSM to disable Force Authentication in the SSO configuration of your account. Our organization has enabled Enforce SSO, and it is the first time I am signing in. When I enter my email address at https://app.oneflow.com, I can’t sign in because I do not have a Oneflow password. If your organisation does not have the JIT user creation feature enabled and has not set a domain that matches the domain of your email address, the only way you can log in to Oneflow is using an IDP login (check Key concepts for more information). Once your user has been registered in Oneflow, you will be able to use https://app.oneflow.com. Yes it's possible, please ask your CSM to add the users to the Enforce SSO Exclusion list. Keep in mind that only users that currently have Oneflow credentials can be listed here. Yes it's possible, please ask your CSM to add the users to the Enforce SSO Exclusion list. Keep in mind that only users that currently have Oneflow credentials can be listed here. We created a user through SSO, so they do not have Oneflow credentials. How can they obtain Oneflow credentials? The user has to go to https://app.oneflow.com, enter their email, and click on Forgot your password? The user will get an email allowing them to create a Oneflow password. We have JIT user creation and group sync enabled, and one of our users (that did not belong to the synced group on the IDP’s side) tried to log in. They got the error message ‘Login disabled’. After adding the user to the synced group on IDP’s side, it is still not working. What can we do? If a user that does not belong to a synced group tries to log in via SSO, the system will create the user in Oneflow’s database, but the system will deactivate them because they do not belong to a synced group. If this happens, it does not help to add the user to the synced group on the IDP’s side because the user is deactivated. In this case, please contact your CSM and ask the user to be activated. We have group sync enabled. When we add/remove users from the groups in IDP, we do not see the changes in Oneflow. Why? Group synchronization related to SSO occurs during the login process. If a user is added/removed from a group on the IDP’s side, the changes will be applied when the user logs in to Oneflow. We recently removed a user from AD, but the user is still in a synced group in Oneflow. Why? SSO group sync occurs in Oneflow every time a user logs in. If the user has been removed from a group, they have to log in so the sync can take place. If the user has been removed from AD altogether, an administrator has to log in to Oneflow and deactivate the user. Once the user has been deactivated, the system will remove them from the group/s. We recently enabled group sync, and now some users cannot log in to Oneflow. Once group sync is enabled, only users belonging to a synced group can log in to Oneflow (your AD might have groups not synced with a Oneflow group). If there are users not belonging to synced groups that need to have access to Oneflow, there are four options:
- Add the users to Enforce SSO Exclusion (only if they already have Oneflow credentials).
- Add the users to one of the synced groups.
- Create a new group in AD, add the users, and sync it with a Oneflow group.
- Disable group sync from the account’s SSO configuration.
We have added a new user to AD in our organization, but they cannot log in, although it has worked previously with other users. Why can’t our new user log in? There might be technical reasons behind it, but chances are that there are no available seats in the account. If there are no seats available, your organization can deactivate another user or buy more seats. We have many users in our AD. Do we have to invite every user using the Invite user function in Oneflow? Is there any other way they can log in to Oneflow directly? They can log in directly to Oneflow. Please ask your CSM to enable JIT user creation for the account. Once enabled, users that are not registered in Oneflow (but registered in AD) can log in to Oneflow and have their Oneflow user created on their first login. Remember that the account has to have available seats for the user to be successfully created There is a synced group with many members, and we want to provide access to some members but not to others. How can we do this? Users can have a role both individually and within a group. In addition, users can belong to different groups and have different roles in those groups. If the number of group members requiring access is small, you can provide them with access individually. However, if the number of group members requiring access is large, it is better to create another group (both in AD and in Oneflow), sync them, and manage the access through the group. We recently added a new user to a group in AD synced to a group in Oneflow. However, the user has not been added to the group in Oneflow. Why?The user needs to log in to Oneflow successfully, and then they will be added to the group automatically. |