Admin GuidesSSO-Only Mode

SSO-Only Mode & the Break-Glass Account

Who this guide is for: Organization Owners (or members holding a custom role that grants the Security page) who want every member of their organization to sign in exclusively through their identity provider (SAML or OIDC), with a single recovery account that can still use a password if the IdP ever fails.

When SSO-only mode is on, the local email & password login is disabled for everyone in your tenant. The login page shows only the Sign in with SSO button. The one exception is the break-glass account — a designated admin or owner who can always sign in with a password, so you are never locked out.

SSO-only mode is off by default. Nothing changes for your users until you turn it on.

Before you begin

You must have both of the following in place before SSO-only mode can be enabled — the toggle stays disabled until they exist:

  1. An enabled identity provider. Configure SAML or OIDC first (see SSO Setup) and make sure it is enabled.
  2. A break-glass account. Designate one active admin or owner who has a local password set (see below).

This two-condition guard exists so a tenant can never accidentally lock itself out: there is always a working IdP and always a password-based way back in.

Step 1 — Designate a break-glass account

  1. Go to Settings → Security, then open the Access tab (SSO-only mode moved here from the SSO page).
  2. Find the SSO-only mode section.
  3. Under Break-glass account, choose an active admin or owner from the dropdown.
    • The admin must have a local password set. Admins who only sign in via SSO (no password) appear greyed out and cannot be selected.
  4. Click Set as break-glass.

Only one break-glass account can exist at a time. Designating a new one replaces the previous designation. The change is recorded in the audit log.

Step 2 — Turn on SSO-only mode

  1. In the same section, toggle Require SSO for all members on.
  2. From now on, all members (except the break-glass account) must sign in through your identity provider.

To turn it back off, toggle it again — disabling is always allowed and has no preconditions.

Configuration reference

SettingWhereDefaultEffect
Break-glass accountSettings → Security → AccessNoneThe single admin or owner allowed to sign in with a password while SSO-only is on
Require SSO for all membersSettings → Security → AccessOffDisables local password login tenant-wide (break-glass exempt)

How it behaves at sign-in

  • Regular users: the login page hides the email/password fields and shows only Sign in with SSO. A password submitted by any other means is rejected server-side.
  • Break-glass account: can always sign in with its email and password, even while SSO-only mode is on. Every break-glass sign-in writes a flagged entry (break_glass_login) to the audit log so SSO-bypass logins are always traceable.
  • Failsafe: if SSO-only is on but no enabled IdP is detected at the login page, the password form is shown anyway — a misconfiguration can never strand your members on a button that goes nowhere.
  • Certificate expiry is a lockout. When your SAML IdP’s signing certificate expires, SSO sign-in fails — and in SSO-only mode that leaves only the break-glass account. EmbayLMS warns every Owner and Admin 60, 30 and 7 days ahead (in-app + email), shows the countdown on Settings → Single Sign-On, and flags your tenant to Embay support as a lockout risk. Renewing takes a minute — see Keep the signing certificate current.

Security & compliance notes

  • The break-glass mechanism satisfies the SSO-lockout recovery control (PRD §5.1.1). Keep the break-glass credentials safe and rotate them periodically.
  • All changes (designating a break-glass account, enabling/disabling SSO-only) and every break-glass login are written to the audit log (SOC 2 CC6.3).

Troubleshooting

SymptomCauseFix
The Require SSO toggle is disabledNo enabled IdP, or no break-glass accountEnable an IdP and designate a break-glass account first
An account is greyed out in the break-glass dropdownThat admin or owner has no local passwordHave them set a password, or choose a different account
A member reports they cannot log in after enabling SSO-onlyThey were using a local passwordThey must now use Sign in with SSO; only the break-glass account keeps password login
You are locked out and SSO is downIdP failureSign in with the break-glass account’s email + password, then fix or disable the IdP
Every SSO sign-in fails and the SSO page shows the certificate as ExpiredThe IdP’s signing certificate expired or was rotatedSign in with the break-glass account, then paste the current certificate in Settings → Single Sign-On (how)