Friction

Pain point · Permissions & security · Blocks work

Authentication flow steps skipped after external IdP login

1 source thread · first seen 2022-02

Summary

OTP and deny-access steps in the browser flow are not executed for users coming from external identity providers, and the client rather than the IdP should decide.

Affects
Admins with external identity providers

Evidence

Excerpts are copied word for word from the source; follow the link to read it in full.

“Client MUST decide about the authedication flow NOT the Identity Provider”

Report this item