So we've just got started using the multi-org, and...
# ask-questions
t
So we've just got started using the multi-org, and we are having a bit of trouble. When a new user completes SSO sign-on, they get presented with a screen to
Create an Organisation
, is that expected?
I would have expected they have to be assigned to an Org by an admin, the user can create a new Org and even the superAdmin user cannot access it as they are not a member
f
no, that's not expected
what SSO provider are you using?
t
Cognito
f
you were able to get that setup?
t
Yes - but with a lot of trial and error
f
okay, cool - we can update the docs for that
t
nice
f
are you wanting to only use SSO?
t
what do you mean sorry?
f
when you add SSO, we don't turn off user/password logins
which can violate some policies
t
since we have enabled SSO, we just get instant redirect
even logout, bounces you directly back to the OIDC login flow and back in again
f
perhaps we can set up some time to help you debug this
t
yeah that would be good sometime next week, i know there are some docs coming for multi-org so it would be interesting to see that
for reference, we are running this in ECS, one container for UI/API and another for proxy
they are communicating fine and the platform works pretty well, but we are trying to tie up this last bit with orgs so that we can control which if any we can auto-add them to
f
yep
dm me with some times that work for you
t
there is a thought in my head it could well be "verified" status of users in Cognito, as those attributes are not set correctly for the people logging in
so i'll play around with that some more and let you know the result
but i'm around anytime 2pm - 5:30pm next week UK time