<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question SSO Auth Options - Insight Needed in Community Central forum</title>
    <link>https://www.servicenow.com/community/community-central-forum/sso-auth-options-insight-needed/m-p/3242543#M2847</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;good day! I'm keen to understand how to configure this kind of set-up as I'm still grasping the concepts of ServiceNow's SSO:&lt;/P&gt;&lt;P&gt;If a user is part of an SSO group,&lt;/P&gt;&lt;P&gt;-allow login with username &amp;amp; password&lt;/P&gt;&lt;P&gt;If not part of group,&lt;/P&gt;&lt;P&gt;-need to login via provider&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We found this OOB auth policy context called "SSO - ACR Context" and we thought changing the Policy Condition: "Allow Non Local Login Users" to&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ZackZap_0-1745198942269.jpeg" style="width: 400px;"&gt;&lt;img src="https://www.servicenow.com/community/image/serverpage/image-id/436493i992358A7AF1C40DA/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ZackZap_0-1745198942269.jpeg" alt="ZackZap_0-1745198942269.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;would allow this to take effect. Am I missing a config somewhere?&lt;/P&gt;&lt;P&gt;Also checked the documentation for reference but I'm still quite confused:&lt;/P&gt;&lt;P&gt;&lt;A title="https://www.servicenow.com/docs/bundle/washingtondc-platform-security/page/integrate/single-sign-on/concept/sso-acct-recovery.html" href="https://www.servicenow.com/docs/bundle/washingtondc-platform-security/page/integrate/single-sign-on/concept/sso-acct-recovery.html" target="_blank" rel="noopener noreferrer"&gt;https://www.servicenow.com/docs/bundle/washingtondc-platform-security/page/integrate/single-sign-on/concept/sso-acct-recovery.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your help and insight would be appreciated. Thanks!&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 21 Apr 2025 01:40:07 GMT</pubDate>
    <dc:creator>Zack Zap</dc:creator>
    <dc:date>2025-04-21T01:40:07Z</dc:date>
    <item>
      <title>SSO Auth Options - Insight Needed</title>
      <link>https://www.servicenow.com/community/community-central-forum/sso-auth-options-insight-needed/m-p/3242543#M2847</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;good day! I'm keen to understand how to configure this kind of set-up as I'm still grasping the concepts of ServiceNow's SSO:&lt;/P&gt;&lt;P&gt;If a user is part of an SSO group,&lt;/P&gt;&lt;P&gt;-allow login with username &amp;amp; password&lt;/P&gt;&lt;P&gt;If not part of group,&lt;/P&gt;&lt;P&gt;-need to login via provider&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We found this OOB auth policy context called "SSO - ACR Context" and we thought changing the Policy Condition: "Allow Non Local Login Users" to&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ZackZap_0-1745198942269.jpeg" style="width: 400px;"&gt;&lt;img src="https://www.servicenow.com/community/image/serverpage/image-id/436493i992358A7AF1C40DA/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ZackZap_0-1745198942269.jpeg" alt="ZackZap_0-1745198942269.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;would allow this to take effect. Am I missing a config somewhere?&lt;/P&gt;&lt;P&gt;Also checked the documentation for reference but I'm still quite confused:&lt;/P&gt;&lt;P&gt;&lt;A title="https://www.servicenow.com/docs/bundle/washingtondc-platform-security/page/integrate/single-sign-on/concept/sso-acct-recovery.html" href="https://www.servicenow.com/docs/bundle/washingtondc-platform-security/page/integrate/single-sign-on/concept/sso-acct-recovery.html" target="_blank" rel="noopener noreferrer"&gt;https://www.servicenow.com/docs/bundle/washingtondc-platform-security/page/integrate/single-sign-on/concept/sso-acct-recovery.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your help and insight would be appreciated. Thanks!&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 01:40:07 GMT</pubDate>
      <guid>https://www.servicenow.com/community/community-central-forum/sso-auth-options-insight-needed/m-p/3242543#M2847</guid>
      <dc:creator>Zack Zap</dc:creator>
      <dc:date>2025-04-21T01:40:07Z</dc:date>
    </item>
    <item>
      <title>Re: SSO Auth Options - Insight Needed</title>
      <link>https://www.servicenow.com/community/community-central-forum/sso-auth-options-insight-needed/m-p/3242597#M2851</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/613903"&gt;@Zack Zap&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If SSO is configured successfully, you can set\create the property "&lt;STRONG&gt;glide.sso.acr.enabled&lt;/STRONG&gt;" as "false". Then users can login with local login as well. Reference KB:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://support.servicenow.com/kb?id=kb_article_view&amp;amp;sysparm_article=KB0997746" target="_blank"&gt;https://support.servicenow.com/kb?id=kb_article_view&amp;amp;sysparm_article=KB0997746&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 05:04:08 GMT</pubDate>
      <guid>https://www.servicenow.com/community/community-central-forum/sso-auth-options-insight-needed/m-p/3242597#M2851</guid>
      <dc:creator>Shree_G</dc:creator>
      <dc:date>2025-04-21T05:04:08Z</dc:date>
    </item>
    <item>
      <title>Re: SSO Auth Options - Insight Needed</title>
      <link>https://www.servicenow.com/community/community-central-forum/sso-auth-options-insight-needed/m-p/3246016#M2882</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/86085"&gt;@Shree_G&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the reply! I'm not too comfortable deactivating this system property due to the security implications, unfortunately. Also, this may not cover the:&lt;BR /&gt;&lt;EM&gt;"If a user is part of an SSO group,&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;-allow login with username &amp;amp; password&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;If not part of group,&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;-need to login via provider"&lt;BR /&gt;&lt;/EM&gt;part of the requirement. Thank you nonetheless. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Apr 2025 02:09:40 GMT</pubDate>
      <guid>https://www.servicenow.com/community/community-central-forum/sso-auth-options-insight-needed/m-p/3246016#M2882</guid>
      <dc:creator>Zack Zap</dc:creator>
      <dc:date>2025-04-24T02:09:40Z</dc:date>
    </item>
  </channel>
</rss>

