You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The administrative console authenticates its own logins today (SchemaForge user store, argon2). Operators already carry directory identity through the Graph sync, but a console administrator signs in with a console-local credential, so directory conditional-access policy (including MFA) does not govern console sign-in.
Add OIDC federation of console login to the deployment's directory (Entra ID first), so:
console sign-in is an OIDC code flow against the tenant's IdP, and the IdP's conditional-access/MFA policy applies;
console-local passwords can be disabled per organization once federation is enabled.
Administration is CLI-first (SchemaForge CLI against the control plane's API), so federation lands at the token-issuance layer rather than a web sign-in page; the login store stays as the break-glass path for platform_admin only.
The administrative console authenticates its own logins today (SchemaForge user store, argon2). Operators already carry directory identity through the Graph sync, but a console administrator signs in with a console-local credential, so directory conditional-access policy (including MFA) does not govern console sign-in.
Add OIDC federation of console login to the deployment's directory (Entra ID first), so:
Administration is CLI-first (SchemaForge CLI against the control plane's API), so federation lands at the token-issuance layer rather than a web sign-in page; the login store stays as the break-glass path for
platform_adminonly.