Skip to main content

Restrict Local Login when using SSO

We use Azure for SSO internally. 2 Factor is performed on the Azure login.
The downside to this is Hudu requires the user have a local login regardless. So I have Duo set up for the sole purpose, that, just in case my techs try to login locally instead of SSO, they will get 2 factor.
Option to create users with no local login ability (SSO only) would be ideal.

2 comments

Log in to comment and vote

Comments2

  • Yellow Oak

    •

    Dec 29, 2022

    This is important for security. See the recent IT-Glue incident.

    Somehow credentials got leaked. All us SSO users where pretty calm until we found out that even SSO users DO have a password set which can be used to login by bypassing the SSO screen with a url parameter.

    Not cool.

    If a user has logged in via SSO at any point in time, local auth should be disabled for this user.

    • Black Quasar

      •

      Dec 30, 2022

      Jörn R.: Disable password sign-in for non-admins.

      If you're self-hosted, you can also disable access to yoursite.com/admin/sign_in unless your SSO goes down, then enable it temporarily.

      I also have the link hidden in custom CSS just so it isn't just sitting in plain view for people to wonder about.