Hi Jared, I've been doing some roadmap planning for the coming year with the Identity and Access Management team. This item (Exception support for "SSO only" login setting) is on the roadmap and we have already had some initial discussions on the design approach we will be taking. At this point, it is still a few months away from implementation, due to other priorities, but the requirement and need is fully understood.
Original Message:
Sent: 12-17-2024 23:07
From: Jared Russell
Subject: Password Madness!
Hey Becky! Was that idea ever implemented?
------------------------------
Jared Russell
Cloud Engr
Original Message:
Sent: 12-07-2023 15:11
From: Becky Powell
Subject: Password Madness!
Hi Andrew, thanks for contributing to the Community! I think you might be interested in this idea we're developing, that will allow you to enforce SSO for everyone except key administrative users.
Per your feedback about the generic password failure message - I understand your frustration but this is by design. We purposely don't give information that could enable a hacker or bad actor to better target their attack.
Please do let us know if there's anything else about the password management experience that you think we can improve. Cheers!
------------------------------
Becky Powell
Director, Product Management
Genesys - Employees
Original Message:
Sent: 12-07-2023 04:28
From: Andrew Lewis
Subject: Password Madness!
Blair, that will work around this and they don't even tell the user what the issue is when they try to change the password, even better (:>
------------------------------
Andrew Lewis
Health Management Ltd
Original Message:
Sent: 12-07-2023 03:49
From: Blair Wilkinson
Subject: Password Madness!
Hello Andrew
My reading of this is your main issue is that you cannot enforce SSO because you require to have 'break glass' accounts for Admin. Therefore you still have the native login page and users can reset password and get access that way.
A potential 'trick' is to make the password strength rules difficult such as 20 characters https://help.mypurecloud.com/articles/set-password-requirements/
I added an idea for break glass accounts recently for the MFA feature but equally it applies to SSO. There was a related idea for SSO from years back but I have not been able to find it now...
https://genesyscloud.ideas.aha.io/ideas/AMIAM-I-38
------------------------------
Thanks and regards
Blair Wilkinson
CVT (Global) Pty Ltd
Original Message:
Sent: 12-06-2023 10:22
From: Andrew Lewis
Subject: Password Madness!
Genesys have just released a feature to allow users to change their cloud password, Great i hear you all say. But no its not so great as they as usual haven't done what they have said, in that the release notes it says "This change does not affect SSO (single sign-on) users." Well it does if you use SSO and have the cloud login box as well (For admins to use to diagnose issues) then everyone that has been logged out of Genesys will try their Windows credentials in the cloud login box then reset the cloud password and not use SSO.
The should be a permission to disable password reset.
#SystemAdministration
------------------------------
Andrew Lewis
Health Management Ltd
------------------------------