on 2022 Mar 16 11:05 AM
Hello experts,
We have TFA configured for every login from different device/country. now we are implementing sso with external idp using SAML. where we are facing issue with account linking for saml user.
case is, if user is already have site identity at CDC, when user tries to use saml sign in option from different device there will be identity conflict & cdc triggers account link flow.
now because of TFA required for the account which is trying to link saml user is not supported, this is also mentioned in cdc documentation.
1. To make the linking happen, we have to disable the TFA which is not serving purpose of configuring it at first.
2. If we chose option by not linking two identities, CDC is asking for TFA two time within one device for same user.
Is there any alternative in option 1 apart from option 2?
Thanks.
Rohit
Request clarification before answering.
Hi Rohit,
My suggestion is:
With this setup in place:
Hope this makes sense.
Igal
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
| User | Count |
|---|---|
| 4 | |
| 2 | |
| 1 | |
| 1 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.