Limit Google CFA Access

Hey there, I setup Google (not workspace) as an identity provider following the instructions in the documentation and I setup an access control for allowed emails. When I tested my connection I seem to be able to login with any email but this doesn't apply to other identity providers last i checked. Is there anything i need to turn on or modify to make it work
25 Replies
Chaika
Chaika2w ago
What's your policy look like?
Chaika
Chaika2w ago
You mean you added one time pin as an option or what exactly do you mean? All you should need is an allow policy only allowing specific emails, and as long as you don't have any other policies, only included emails would pass
4d62
4d622w ago
yea I set the one time pin and the issue fixed itself. I know its weird. let me try to delete the one time pin and check again ok so. I can't login on app launcher but I can login on apps even if I use the access policy which restricts email
Chaika
Chaika2w ago
hmm, what does your application look like? Just a single allow policy? You don't have automatic auth and WARP on, for example, right?
4d62
4d622w ago
no the application is just an openid integration and the theres just one access policy yea. Automatic auth and warp are not turned on
Chaika
Chaika2w ago
you're not using the normal google identity provider, you're using osme custom openid one instead?
4d62
4d622w ago
i must have misread. no im using the default google identity provider from the google cloud console
Chaika
Chaika2w ago
oh, well yea for self-hosted applications if all you have is a single allow policy with includes, have to match at least one of the includes to be allowed in. If you're saying that is the case would be helpful to have some screenshots of your exact config
4d62
4d622w ago
yea lemme post some
4d62
4d622w ago
@Chaika
No description
No description
No description
4d62
4d622w ago
(doesnt affect SAAS apps only selfhosted)
Chaika
Chaika2w ago
and so in that policy, you just have the access group, and that access group is set as Include and has Include: Emails inside of it?
4d62
4d622w ago
yea just this
No description
Chaika
Chaika2w ago
are those domains or emails? If domains there's a proper Emails Ending In selector
Want results from more Discord servers?
Add your server