Pain point · Permissions & security · Blocks work
Authentication flow steps skipped after external IdP login
1 source thread · first seen 2022-02
Summary
OTP and deny-access steps in the browser flow are not executed for users coming from external identity providers, and the client rather than the IdP should decide.
- Affects
- Admins with external identity providers
Evidence
Excerpts are copied word for word from the source; follow the link to read it in full.
“Client MUST decide about the authedication flow NOT the Identity Provider”