Skip to content

Commit 51569a8

Browse files
authored
ENGDOCS-1314 (docker#17174)
* ENGDOCS-1314 * capz
1 parent 7606327 commit 51569a8

File tree

1 file changed

+7
-0
lines changed

1 file changed

+7
-0
lines changed

single-sign-on/manage/index.md

+7
Original file line numberDiff line numberDiff line change
@@ -61,6 +61,13 @@ When you disable SSO, you can delete the connection to remove the configuration
6161

6262
## Manage users
6363

64+
>**Important**
65+
>
66+
> SSO has Just-In-Time (JIT) Provisioning enabled by default, but this can be changed on a per-app basis. To prevent auto-provisioning users, you can create a security group in your IdP and configure the SSO app to authenticate and authorize only those users that are in the security group. Follow the instructions provided by your IdP:
67+
> - [Okta](https://help.okta.com/en-us/Content/Topics/Security/policies/configure-app-signon-policies.htm)
68+
> - [AzureAD](https://learn.microsoft.com/en-us/azure/active-directory/develop/howto-restrict-your-app-to-a-set-of-users)
69+
{: .important}
70+
6471
### Add guest users when SSO is enabled
6572

6673
To add a guest to your organization in Docker Hub if they aren’t verified through your IdP:

0 commit comments

Comments
 (0)