What is this about?
If you enable mandatory SSO, employees can only log in via your IdP (e.g., Entra/Azure AD). Logging in using email and password is disabled.
What changes specifically?
softgarden login: Only possible via SSO.
"Forgot password" no longer works.
Existing local passwords are rendered ineffective.
User creation: New users must be assigned via your AD/IdP.
Invitations via softgarden user management are useless, as they would create a secondary local account that is not permitted to log in.
Tenant & role: Ideally passed via SSO claim.
Otherwise, the user is placed in the main tenant with the most restricted role (usually Reviewer).
Candidate portal: Unaffected. Applicants continue to use their softgarden accounts (no SSO).
Availability: If your IdP goes down, no one can access softgarden.
FAQ
Q: Can I use specific local exceptions? A: No. If you absolutely require local accounts, you should not enable the mandatory SSO requirement.
Q: What happens to local users who have already been invited? A: They will no longer be able to log in using a password. Assign them to the softgarden app within your IdP. Users created locally beforehand can be mapped to the new SSO user—no data will be lost.
Q: What is the best practice for the rollout? A: Test groups/claims beforehand, assign a pilot group, and communicate the change internally (e.g., "SSO only starting on date X").
