Organization Should Use Single-Sign-On
policy name: organization_not_using_single_sign_on
severity: MEDIUM
Description
It is recommended to enable access to an organization via SAML single sign-on (SSO) by authenticating through an identity provider (IdP). This allows for central account control and for timely access revocations.
Threat Example(s)
Not using an SSO solution makes it more difficult to track a potentially compromised user’s actions across different systems, prevents the organization from defining a common password policy, and makes it challenging to audit different aspects of the user’s behavior.
Remediation
- Make sure you have admin permissions
- Go to the organization settings page
- Enter ‘Authentication security’ tab
- Toggle on ‘Enable SAML authentication’
- Fill in the remaining SSO configuration as instructed on the screen
- Click ‘Save’