cloudscaleKnowledge Base
Single Sign-On With Your Own Identity Provider
Use SSO with the connection of our cloud control panel to your "OpenID Connect"-compatible IDP.
When attempting to sign up or log in to our control panel, users with an email address from your email domain can be redirected to your IDP. Once they have authenticated themselves according to your IDP's requirements, they will be redirected back to our control panel and will be logged in there as well.
To this end, our control panel can be connected to external "OpenID Connect"-compatible identity providers, such as Keycloak. If you would like to set this up for your email domain, please contact our support.
Notes and tips:
- By logging your organization members into our control panel via your own IDP, you can technically enforce 2FA directly on the IDP if desired.
- You can define directly in your IDP whether a certain person is actually authorized to log into our control panel. This will also enable you to maintain control when employees join or leave your company.
- If you operate your IDP in our cloud, make sure that you can still take the required repair measures in the case of its failure. This is why we recommend that you include a superuser in your organization that does not depend on the same IDP.