ShlomoKatz (Customer) asked a question.

We are going thgough a M&A, and the some users are being removed from the HR feed.
They still require SSO Authenticate to G&L eventhough they are "deleted" as an identity.

Example:

User is removed from HR feed and now shows as deleted in Identity, however, they still need to be able to log into G&L for services.

How can I configure G&L to allow autheication even if "deleted" as an Identity but still has active account?


  • when identity is marked as deleted or as terminated, you will not be able (nor should you be able) to login to GL.

    From a security perspective, why should you be able to login if the authoritative source states that the identity is terminated/deleted.

    Selected as Best
  • just to understand.

    The authentication is configured with SSO SAML and you want to allow users who are marked as deleted in GL to login to GL?

    • ShlomoKatz (Customer)

      Yes.

      I tested AD credentials in Dev without "SSO" and I still cannot authenticate.

      • well, that's the expected behavior.

        I'm not familiar with a way to work around that.

         

      • ShlomoKatz (Customer)

        Right, so I can tell my boss "Deleted = no authentication"?

      • when identity is marked as deleted or as terminated, you will not be able (nor should you be able) to login to GL.

        From a security perspective, why should you be able to login if the authoritative source states that the identity is terminated/deleted.

        Selected as Best