Skip to content

Federate admin console login to the tenant directory via OIDC #45

Description

@rrrodzilla

The administrative console authenticates its own logins today (SchemaForge user store, argon2). Operators already carry directory identity through the Graph sync, but a console administrator signs in with a console-local credential, so directory conditional-access policy (including MFA) does not govern console sign-in.

Add OIDC federation of console login to the deployment's directory (Entra ID first), so:

  • console sign-in is an OIDC code flow against the tenant's IdP, and the IdP's conditional-access/MFA policy applies;
  • a console login maps to the same directory object the operator record carries, closing the manual-deactivation gap in Directory sync cannot deactivate console logins: user store has no tenant column #32 at the sign-in layer as well;
  • console-local passwords can be disabled per organization once federation is enabled.

Administration is CLI-first (SchemaForge CLI against the control plane's API), so federation lands at the token-issuance layer rather than a web sign-in page; the login store stays as the break-glass path for platform_admin only.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions