You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It would be nice to allow system admins to authenticate via an idp instead of just a username and password to help with access management when a user leaves the organisation. Maybe via a group claim or set specific mailbox users to be system administrators?
Motivation
By implimenting this, it would allow organisations to give/remove someone admin access from a single location. It would also mean when they disable their idp account, they wouldn't need to worry about forgetting to disable access from within mailcow.
Additional context
No response
The text was updated successfully, but these errors were encountered:
I agree. Users should be fetched from one or more (internal/external) IdP. And authorization should be configured in one place via the mailcow admin. Group claim to set permissions would be very good.
I successfully run a beta instance with Keycloak as an external IdP for a while now. It is working really good so far. Except SoGO not offering a logout button to the user.
Summary
It would be nice to allow system admins to authenticate via an idp instead of just a username and password to help with access management when a user leaves the organisation. Maybe via a group claim or set specific mailbox users to be system administrators?
Motivation
By implimenting this, it would allow organisations to give/remove someone admin access from a single location. It would also mean when they disable their idp account, they wouldn't need to worry about forgetting to disable access from within mailcow.
Additional context
No response
The text was updated successfully, but these errors were encountered: