11.40 code - I have ran into an issue where the local break glass account is unable to be used when SAML is enabled. This apparently is due to the fact that the email associated with the local account is in fact in the IdP and once it detects that, there’s no way to “cancel” the redirect. Is there no way to disable SAML for specific accounts regardless of whether the email account exists in the external IdP?
Since the email is a required field for all accounts and having a valid email for such an account makes sense BUT you have to have it syncing in order to actually authenticate and manage that mailbox, seems like a catch-22. Security prefers SSO.
Plus if the external provider is unavailable for whatever reason, nobody, even the break glass account can login.
I do have a case open with this but so far we haven’t found a solution.


