Articles in this section

Require SSO for the account owner

The account owner can always sign in to integrator.io with an email and password, even when single sign-on (SSO) is required for every other user. This article explains how to close that last gap by requiring SSO for the account owner too using the Require SSO for account owner setting. If you want to require tenant-wide SSO, then you can require SSO for the account owner and require SSO for all users

Caution

Turning on the Require SSO for account owner setting removes the owner's always-available backup manual sign-in. So, turn it on only after confirming SSO works, and the owner's account has multi-factor authentication (MFA) enabled.

Prerequisites

Why require SSO for the account owner 

The account owner can otherwise always sign in with an email and password, even when SSO is required for everyone else. Reasons to close this gap by turning on the Require SSO for account owner setting include:

  • Compliance. Security reviews such as SOC 2 or ISO 27001 may require proof that every sign-in goes through your identity provider. A standing password for the owner breaks that.
  • Consistent rules. Controls your identity provider enforces, such as MFA, device checks, and location limits, apply only to sign-ins that go through it. The owner's password sign-in skips all of them.
  • Faster offboarding. If the owner role changes hands, turning off access in your identity provider fully locks out the previous owner only when no separate password still works.
  • Fewer passwords to protect. This removes one more password on a highly privileged account that could be phished, reused, or leaked.

A few things to keep in mind

  • Off-domain account owners. If the owner's email isn't on a domain your SSO provider covers, such as a personal Gmail address, the sign-in check fails, and you can't turn this setting on. Celigo still recommends the account owner as your backup for manual sign-in, provided that account has a strong password and MFA turned on.
  • The backup manual sign-in still needs a company email. Celigo doesn't allow personal or free email addresses, such as @gmail.com, for this purpose, even for the owner. You can't use a personal email to work around the off-domain limitation above.
  • There's no way to name a different backup user. The account owner is always the fallback for manual sign-in; you can't assign that role to another admin.
  • Only the owner can turn their own setting on or off. Administrators can turn Require SSO for all users on or off, but not Require SSO for account owner.
  • The manual sign-in URL differs by region (US and EU). For the correct URL in each region, see Troubleshoot sign in.
  • If you're an owner or admin on more than one Celigo account, check with your Celigo contact, since this setup can work differently across accounts.

How to require SSO for the account owner

To require SSO for the account owner:

  1. Sign in to integrator.io as the owner or admin.
  2. Go to Account, and select Security.
  3. In the Single sign-on (SSO) section, select the Require SSO for account owner checkbox.
  4. Select Verify & Save.

Once authentication is verified, integrator.io confirms that the SSO setting has been updated.

What stays the same

  • Manual sign-in (?manualMode=true) isn't removed. It just stops working for the owner once Require SSO for account owner is turned on.
  • API tokens work the same either way.

If SSO goes down

If your SSO provider becomes unavailable and Require SSO for account owner is turned on, contact Celigo Support. They can help you regain access through an identity-verified process.

Learn more