Manage Single Sign-On for a company
Early Access
Docker Admin is an early access product.
It's currently available to all company owners and organization owners that have a Docker Business or Docker Team subscription. You can still manage companies and organizations in Docker Hub. For details about managing companies or organizations in Docker Hub, see Administration and security.
Follow the steps on this page to manage SSO for your company. To manage SSO for an organization, see Manage SSO for an organization.
Manage organizations
Connect an organization
- Sign in to Docker Adminopen_in_new.
- Select your company in the left navigation drop-down menu, and then select SSO & SCIM.
- In the SSO connections table, select the Action icon and then Edit connection.
- Select Next to navigate to the section where connected organizations are listed.
- In the Organizations drop-down, select the organization to add to the connection.
- Select Next to confirm or change the default organization and team provisioning.
- Review the Connection Summary and select Save.
Remove an organization
- Sign in to Docker Adminopen_in_new.
- Select your company in the left navigation drop-down menu, and then select SSO & SCIM.
- In the SSO connections table, select the Action icon and then Edit connection.
- Select Next to navigate to the section where connected organizations are listed.
- In the Organizations drop-down, select Remove to remove the connection.
- Select Next to confirm or change the default organization and team provisioning.
- Review the Connection Summary and select Save.
Manage domains
Remove a domain from an SSO connection
- Sign in to Docker Adminopen_in_new.
- Select your company in the left navigation drop-down menu, and then select SSO & SCIM.
- In the SSO connections table, select the Action icon and then Edit connection.
- Select Next to navigate to the section where the connected domains are listed.
- In the Domain drop-down, select the x icon next to the domain that you want to remove.
- Select Next to confirm or change the connected organization(s).
- Select Next to confirm or change the default organization and team provisioning selections.
- Review the Connection Summary and select Save.
Note
If you want to re-add the domain, a new TXT record value is assigned. You must then complete the verification steps with the new TXT record value.
Manage SSO connections
Edit a connection
- Sign in to Docker Adminopen_in_new.
- Select your company in the left navigation drop-down menu, and then select SSO & SCIM.
- In the SSO connections table, select the Action icon.
- Select Edit connection to edit your connection.
- Follow the on-screen instructions to edit the connection.
Delete a connection
- Sign in to Docker Adminopen_in_new.
- Select your company in the left navigation drop-down menu, and then select SSO & SCIM.
- In the SSO connections table, select the Action icon.
- Select Delete connection.
- Follow the on-screen instructions to delete a connection.
Deleting SSO
When you disable SSO, you can delete the connection to remove the configuration settings and the added domains. Once you delete this connection, it can't be undone. Users must authenticate with their Docker ID and password or create a password reset if they don't have one.
Manage users
Important
SSO has Just-In-Time (JIT) Provisioning enabled by default. This means your users are auto-provisioned into a team called 'Company' within your organization.
You can change this on a per-app basis. To prevent auto-provisioning users, you can create a security group in your IdP and configure the SSO app to authenticate and authorize only those users that are in the security group. Follow the instructions provided by your IdP:
Add guest users when SSO is enabled
To add a guest if they aren’t verified through your IdP:
- Sign in to Docker Adminopen_in_new.
- Select your organization in the left navigation drop-down menu, and then select Users.
- Select Invite.
- Follow the on-screen instructions to invite the user.
Remove users from the SSO company
To remove a user:
- Sign in to Docker Adminopen_in_new.
- Select your organization in the left navigation drop-down menu, and then select Users.
- Select the action icon next to a user’s name, and then select Remove user.
- Follow the on-screen instructions to remove the user.